ManageEngine AD360 Integration Flaw Can Expose User Identity and Role Data


ManageEngine has patched a serious security flaw affecting several identity and access management products when they run as integrated components inside AD360. The vulnerability, tracked as CVE-2026-11374, could let an unauthenticated attacker predict SSO tickets and take over user accounts.

The issue affects ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus in AD360 deployments. According to the ManageEngine advisory, successful exploitation could expose a targeted user’s identity and role information before leading to account takeover.

The flaw matters because AD360 often sits close to core identity infrastructure. ManageEngine describes AD360 as an integrated identity and access management platform for managing user identities, governing access, enforcing security, and supporting compliance across enterprise environments.

What CVE-2026-11374 affects

CVE-2026-11374 affects four ManageEngine products only when they are deployed as integrated components within ManageEngine AD360. Standalone deployments may not face the same exposure path described in the advisory.

The vulnerability sits in the single sign-on flow between AD360 and the integrated products. When a user signs in through AD360 SSO, the system generates an SSO ticket to authenticate the session.

ManageEngine says those SSO tickets could be predicted by an unauthenticated attacker. A valid predicted ticket could then let the attacker access the targeted user’s account context.

ProductAffected versionsFixed versionFix date
ADSelfService Plus6528 and earlier6529June 3, 2026
RecoveryManager Plus6320 and earlier6321June 5, 2026
M365 Manager Plus4816 and earlier4817June 10, 2026
ADAudit Plus8702 and earlier8703June 12, 2026

Why the SSO ticket flaw is risky

The risk comes from predictable authentication material. If an attacker can predict an SSO ticket, they may bypass the normal login process and impersonate a valid user without knowing that user’s password.

The NVD entry says the generated SSO tickets could be predicted by an unauthenticated user, leading to account takeover. NVD also lists ManageEngine’s CVSS 3.1 score as 9.0 with a critical severity rating from the CNA.

The issue includes several weakness categories. The same NVD record lists CWE-287 for improper authentication, CWE-330 for use of insufficiently random values, and CWE-340 for predictable identifiers.

What attackers could gain

ManageEngine says an attacker who successfully predicts a valid SSO ticket could obtain the targeted user’s identity and role information. That access could then lead to takeover of the user’s account under the right conditions.

In an AD360 environment, role data can matter as much as basic identity data. If an attacker learns what permissions a user has, they can better understand which account gives access to sensitive functions, reports, or administrative workflows.

That makes the bug especially important for organizations that use AD360 as a central identity hub. A compromised SSO session can create risk across connected identity, audit, recovery, and Microsoft 365 administration tools.

  • Unauthorized access to identity and role information
  • Potential account takeover through predicted SSO tickets
  • Exposure of administrative context inside AD360-connected products
  • Possible reconnaissance against Active Directory and Microsoft 365 workflows
  • Higher risk in environments with broad or poorly reviewed role assignments

How ManageEngine fixed the issue

ManageEngine says it fixed CVE-2026-11374 by strengthening the way SSO tickets are generated during single sign-on sessions. The goal is to ensure unauthenticated attackers can no longer predict those tickets.

The official advisory credits security researcher 0xmanhnv for reporting the vulnerability through the Zoho BugBounty program. ManageEngine has released service packs for each affected product.

RecoveryManager Plus release notes also confirm the fix in build 6321. The RecoveryManager Plus release notes describe the issue as a flaw in inter-product custom SSO tickets used for seamless authentication between integrated products in the AD360 suite.

Who needs to patch now

Organizations should patch immediately if they run ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, or ADAudit Plus as part of AD360 and use affected builds. The fixed builds are already available through ManageEngine’s service pack channels.

Security teams should not delay the update because the vulnerability requires no prior authentication. The attack complexity is listed as high in the CVSS vector, but the impact can include confidentiality, integrity, and availability compromise.

Admins should also inventory all AD360 integrations, confirm product versions, and check whether any internet-facing or widely accessible management interfaces expose the affected workflow.

Priority actionRecommended step
Patch affected productsUpdate ADSelfService Plus to 6529, RecoveryManager Plus to 6321, M365 Manager Plus to 4817, and ADAudit Plus to 8703 or later.
Review AD360 integrationsConfirm which products use AD360 SSO and whether any affected builds remain in production.
Audit authentication logsLook for unusual SSO activity, unexpected sessions, and abnormal access patterns.
Review rolesCheck privileged accounts and reduce excessive role assignments where possible.
Restrict accessLimit management portals to trusted networks, VPNs, or administrative jump hosts.

What admins should check after updating

Patching closes the ticket-generation weakness, but administrators should still investigate whether suspicious activity occurred before the fix. That review should include SSO logs, admin activity, role changes, and unusual access to reports or configuration pages.

Organizations using ManageEngine AD360 for centralized identity and access management should pay close attention to privileged roles. Accounts with broad permissions create more damage if attackers can impersonate them.

The RecoveryManager Plus release notes add that the flaw could expose user identity and role information and, under certain conditions, lead to account takeover. That makes post-patch monitoring an important part of the response, not an optional step.

Bottom line

CVE-2026-11374 gives security teams a clear priority: find affected ManageEngine AD360 integrations, apply the fixed builds, and review SSO activity. The vulnerability targets trust between integrated identity tools, which makes it more sensitive than a routine application bug.

The fix is already available, and organizations should move quickly. Identity platforms control access to many other systems, so even a narrow SSO weakness can create wider enterprise risk.

After patching, teams should reduce exposed management surfaces, review privileged access, and monitor authentication behavior for signs of attempted abuse.

FAQ

What is CVE-2026-11374?

CVE-2026-11374 is a ManageEngine vulnerability where SSO tickets generated for integrated AD360 products could be predicted by an unauthenticated attacker, potentially leading to account takeover.

Which ManageEngine products are affected by CVE-2026-11374?

The affected products are ADSelfService Plus 6528 and earlier, RecoveryManager Plus 6320 and earlier, M365 Manager Plus 4816 and earlier, and ADAudit Plus 8702 and earlier when deployed as integrated components within AD360.

What can attackers do with this ManageEngine flaw?

An attacker who predicts a valid SSO ticket could obtain user identity and role information and potentially take over the targeted user’s account.

What versions fix CVE-2026-11374?

ManageEngine fixed the issue in ADSelfService Plus 6529, RecoveryManager Plus 6321, M365 Manager Plus 4817, and ADAudit Plus 8703.

What should administrators do after patching?

Administrators should review AD360 integrations, check SSO and authentication logs, audit privileged roles, and restrict access to management portals from untrusted networks.

Readers help support VPNCentral. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more

User forum

0 messages