A high-severity vulnerability, tracked as CVE-2026-11374, has been disclosed in multiple ManageEngine products, ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, when deployed as integrated components within the ManageEngine AD360 suite.
The flaw allows unauthenticated attackers to predict Single Sign-On (SSO) tickets and fully take over targeted user accounts.
ManageEngine AD360 Flaw
The vulnerability exists in the SSO authentication mechanism used when users sign in through AD360’s integrated environment. When a user authenticates via SSO, the system generates tickets to validate that session.
However, researchers found that these SSO tickets could be predicted by an unauthenticated attacker due to weak ticket generation logic.
A successful exploit allows the attacker to obtain the victim’s identity and role information, effectively granting them complete control over the targeted account without ever needing valid credentials.
This type of vulnerability is particularly dangerous in enterprise environments where AD360 serves as a centralized identity and access management (IAM) hub, meaning a single compromised SSO ticket can cascade into access across multiple critical systems.
| Product | Affected Version | Fixed Version | Patch Date |
|---|---|---|---|
| ADSelfService Plus | 6528 and earlier | 6529 | June 3, 2026 |
| RecoveryManager Plus | 6320 and earlier | 6321 | June 5, 2026 |
| M365 Manager Plus | 4816 and earlier | 4817 | June 10, 2026 |
| ADAudit Plus | 8702 and earlier | 8703 | June 12, 2026 |
ManageEngine products are widely deployed across enterprise and government networks globally. AD360 specifically consolidates identity management, password self-service, auditing, and Microsoft 365 administration into a single platform.
A flaw affecting the SSO layer of this suite creates a wide attack surface any unauthenticated actor with network access to the application could silently impersonate privileged users, administrators, or auditors.
Account takeover vulnerabilities of this nature are frequently exploited by threat actors for lateral movement, privilege escalation, and data exfiltration, making timely patching critical.
Mitigation
ManageEngine resolved the issue by strengthening the SSO ticket generation process, ensuring tokens are no longer predictable. Organizations should immediately apply the latest service packs from the official ManageEngine update portals.
Security teams should also audit SSO session logs for any unusual authentication patterns since the affected versions were deployed, as exploitation may leave limited footprints in standard log reviews.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.



