Skip to content

ManageEngine AD360 Account Takeover Vulnerability - 20260629004

Overview

In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to authenticate that session could be predicted by an unauthenticated user, leading to account takeover.

What is vulnerable?

Product(s) Affected Version(s) CVE CVSS Severity
ADSelfService Plus
RecoveryManager Plus
M365 Manager Plus
ADAudit Plus
6528 and earlier
6320 and earlier
4816 and earlier
8702 and earlier
CVE-2026-11374 9.0 Critical

What has been observed?

The WASOC has not received any reports of exploitation of this vulnerability on Western Australian Government networks at the time of writing.

Recommendation

The WASOC recommends administrators apply the solutions as per vendor instructions to all affected devices within expected timeframes (refer Patch Management):