logo

ManageEngine AD360 Integration Flaw Exposes User Identity and Role Information to Attackers

ID: 5db76bbf-5fa5-579e-87e2-22cff783f633

STIX ID: report--5db76bbf-5fa5-579e-87e2-22cff783f633

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-06-25

Date Updated: 2026-06-25

Author: Abinaya

...
...

ManageEngine disclosed CVE-2026-11374, a high-severity flaw in AD360-integrated identity products (ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, ADAudit Plus) where predictable SSO tokens allow unauthenticated attackers to impersonate users and access sensitive identity and audit data; patches were released in early June 2026 and organizations are advised to apply updates and monitor authentication activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.