Vulnerability Intelligence Report
Account Takeover via Predictable SSO Ticket Generation
CVE-2026-11374
In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to authenticate that session could be predicted by an unauthenticated user, leading to account takeover.
No Active Exploit Signals
CVSS Base Score
9.0
CRITICAL
Exploitability:2.3
Impact Score:6.1
EPSS Probability:1.24%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-340 ↗CWE-340: Generation of Predictable Numbers or Identifiers
CWE-330 ↗CWE-330: Use of Insufficiently Random Values
CWE-287 ↗CWE-287: Improper Authentication
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| zohocorp | manageengine_adselfservice_plus | 0 < 6529 (affected) |
| zohocorp | manageengine_recovery_manager_plus | 0 < 6321 (affected) |
| zohocorp | manageengine_m365_manager_plus | 0 < 4817 (affected) |
| zohocorp | manageengine_adaudit_plus | 0 < 8703 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
1.237%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Zohocorp · Vendor · India |
| Reserved | 2026-06-05T12:25:17 |
| Published | 2026-06-23T08:19:30 |
| Last Updated | 2026-06-24T15:48:27 |
Community Chatter & Buzz