CVE-2026-11374

In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to authenticate that session could be predicted by an unauthenticated user, leading to account takeover.

Scoring

Severity
CRITICAL
CVSS base score
9
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS probability
2.52%
CWE
CWE-340, CWE-330, CWE-287
Published
2026-06-23
Last modified
2026-06-24

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs