Session Prediction Vulnerability in ManageEngine Products

⚠️ CVE-Referenzen: CVE-2026-11374
Zohocorp - Manageengine Adselfservice Plus - CRITICAL - CVE-2026-11374. A vulnerability in ManageEngine products allows unauthenticated users to predict single sign-on (SSO) tickets, potentially leading to unauthorized account access. This flaw affects several of their services, including ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, thus presenting significant security risks for organizations relying on these tools.
Quelle: securityvulnerability.io