Junglewise Threat Intelligence

CVE-2026-16053: Zoho ManageEngine M365 Manager Plus path traversal in Exchange Online backup

CVE-2026-16053 · Severity: high · CVSS 8.5 · Published 2026-08-11

Vendors: Zoho.

Executive brief

Zoho ManageEngine M365 Manager Plus and M365 Security Plus are administration tools for managing Microsoft 365 environments. An authenticated user with access to these tools can exploit a path traversal vulnerability in the Exchange Online backup module to delete arbitrary files on the server, causing data loss and service disruption. The vulnerability requires valid credentials but could allow an insider or compromised account to cause significant damage.

Technical details

CVE-2026-16053 is an authenticated path traversal vulnerability in the Exchange Online backup module of ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820. The vulnerability stems from insufficient path validation when processing file and folder paths, allowing an authenticated attacker to traverse the file system and delete arbitrary files. Attack requires valid authentication credentials but no elevated privileges. The impact is loss of data integrity and service availability. The vendor has patched the issue by implementing proper path validation and restricting file operations to valid paths only.

Affected products

  • Zoho ManageEngine M365 Manager Plus below 4820
  • Zoho ManageEngine M365 Security Plus below 4820

Timeline

  • 2026-08-11: disclosed
  • 2026-07-13: patched: Fixed version 4820 released

References