Home
CRITICAL: 9.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:HDefault status
unaffected
Any version before 6529
affected
Default status
unaffected
Any version before 6321
affected
Default status
unaffected
Any version before 4817
affected
Default status
unaffected
Any version before 8703
affected
Description
In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to authenticate that session could be predicted by an unauthenticated user, leading to account takeover.
Problem types
CWE-340: Generation of Predictable Numbers or Identifiers
CWE-330: Use of Insufficiently Random Values
CWE-287: Improper Authentication
Product status
Any version before 6529
Any version before 6321
Any version before 4817
Any version before 8703
References
www.manageengine.com/...assword/advisory/CVE-2026-11374.html