CVE-2026-11374
In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to authenticate that session could be predicted by an unauthenticated user, leading to account takeover.
- Affected products
- Ad360, Adaudit Plus, Adselfservice Plus, O365 Manager Plus, Recovermanager Plus
- CVSS 3.1
- 9.0 CRITICAL
- EPSS
- 2.5% (84th percentile)
- Weakness
- CWE-287, CWE-330, CWE-340
- NVD status
- Awaiting Analysis
- Published
- 2026-06-23
- Attack patterns
- CAPEC-59
- Entry point
- CUSTOM_SSO_TICKET path
- Path
- AppsHome.do
CVE-2026-11374 at NVD
3 known exploits for CVE-2026-11374
Proof-of-concept code and exploit modules indexed by Sploitus