Executive brief
ManageEngine AD360 and its integrated components are used by organizations to manage Active Directory, backups, and Microsoft 365 environments. A vulnerability in how these products handle Single Sign-On (SSO) allows unauthorized individuals to predict authentication tickets. If exploited, an attacker could take over user accounts, potentially gaining administrative access to sensitive directory services and corporate data.
Technical details
A vulnerability exists in ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus when deployed as integrated components within ManageEngine AD360. The root cause is the use of insufficiently random values (CWE-330) and predictable identifiers (CWE-340) during the generation of Single Sign-On (SSO) tickets. An unauthenticated remote attacker can predict valid SSO tickets to bypass authentication (CWE-287) and obtain a targeted user's identity and role information. This leads to full account takeover. The vulnerability is addressed in ADSelfService Plus 6529, RecoveryManager Plus 6321, M365 Manager Plus 4817, and ADAudit Plus 8703.
Affected products
- ManageEngine ADSelfService Plus <= 6528
- ManageEngine RecoveryManager Plus <= 6320
- ManageEngine M365 Manager Plus <= 4816
- ManageEngine ADAudit Plus <= 8702
Timeline
- 2026-06-03: patched: Fixed in ADSelfService Plus 6529
- 2026-06-05: patched: Fixed in RecoveryManager Plus 6321
- 2026-06-10: patched: Fixed in M365 Manager Plus 4817
- 2026-06-12: patched: Fixed in ADAudit Plus 8703
- 2026-06-23: advisory: NVD publication date