CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2026-11374

CVSS 9.0v3.1pub. 2026-06-23upd. 2026-06-24

In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to authenticate that session could be predicted by an unauthenticated user, leading to account takeover.

🤖 AI Analysis
How it works

The SSO ticket generation mechanism used by the mentioned ManageEngine products contains a vulnerability consisting of insufficient randomness or a predictable algorithm for creating token values (CWE-330, CWE-340). An unauthorized user, without the need to possess any authentication credentials, is able to guess or calculate the value of a valid SSO ticket generated for another session. Using such an obtained token, the attacker can bypass authentication mechanisms (CWE-287) and gain access to the victim's account.

Impact

An attacker can fully take over the account of any user of the compromised system, gaining access to their privileges, data, and identity management and directory resource capabilities. Due to the range of products (password management, AD audit, M365 management), the consequences may include compromise of the entire directory infrastructure of the organization.

Mitigation & patch

Patches available from the vendor should be applied according to references published at: https://www.manageengine.com/products/self-service-password/advisory/CVE-2026-11374.html

Who is affected

ManageEngine ADSelfService Plus, ManageEngine RecoveryManager Plus, ManageEngine M365 Manager Plus, and ManageEngine ADAudit Plus — specific versions indicated in vendor references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Auth Bypass
CWE
References