Executive brief
ManageEngine ADAudit Plus, a tool used by organizations to monitor and audit changes in Active Directory and file servers, contains a critical security flaw. An unauthenticated attacker can remotely execute malicious code on the server, potentially leading to a full takeover of the auditing system and access to sensitive network logs. This could allow an adversary to disrupt operations, steal data, or hide their tracks during a broader network intrusion.
Technical details
ManageEngine ADAudit Plus is affected by an unauthenticated remote code execution (RCE) vulnerability in its agent API. The flaw stems from a combination of an authentication bypass and a path traversal vulnerability (CWE-78, CWE-22). An attacker can exploit these weaknesses over the network without any prior credentials or user interaction to execute arbitrary OS commands on the host system. The vulnerability is fixed in build 8606; users may also need to update Windows agents to version 7060 or later and update all Mac agents to ensure full remediation.
Affected products
- Zohocorp ManageEngine ADAudit Plus All builds below 8606
Timeline
- 2026-04-17: patched: Build 8606 released to address the vulnerability.
- 2026-07-23: disclosed: CVE-2026-6516 published.