Sploitus

CVE-2026-11374

3 known exploits for CVE-2026-11374

In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to authenticate that session could be predicted by an unauthenticated user, leading to account takeover.

CVSS 3.1
9.0 CRITICAL
EPSS
2.5% (84th percentile)
Weakness
CWE-287, CWE-330, CWE-340
NVD status
Awaiting Analysis
Published
2026-06-23
Attack patterns
CAPEC-59
Entry point
CUSTOM_SSO_TICKET path
Path
AppsHome.do
CVE-2026-11374 at NVD
Authoritative description, scoring and affected products

3 known exploits for CVE-2026-11374

Proof-of-concept code and exploit modules indexed by Sploitus