CVE-2026-11374

In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to authenticate that session could be predicted by an unauthenticated user, leading to account takeover.
Configurations

No configuration.

History

23 Jun 2026, 09:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-23 09:16

Updated : 2026-06-24 17:16


NVD link : CVE-2026-11374

Mitre link : CVE-2026-11374

CVE.ORG link : CVE-2026-11374


JSON object : View

Products Affected

No product.

CWE
CWE-287

Improper Authentication

CWE-330

Use of Insufficiently Random Values

CWE-340

Generation of Predictable Numbers or Identifiers