← back
CVE-2026-11374criticalCWE-287CWE-330CWE-340

Account Takeover via Predictable SSO Ticket Generation

48Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 9epss 2.0%
from disclosure to weapon27 days
Published on NVDJun 23
1st PoC+27d
exploitation probability
2.0%top 22% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to authenticate that session could be predicted by an unauthenticated user, leading to account takeover.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.