Sceawere

Vulnerability Detail

CVE-2026-16053UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

ManageEngine M365 Path Traversal

Vulnerability Metadata

Severity
High
Score / CVSS
8.5
Creation Date
3h ago
Vendor
Zohocorp
Product
ManageEngine M365 Manager Plus
Attack Type
CWE-23 Relative path traversal
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H
Attack Complexity
LOW

Narrative and Response

Description

Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to Authenticated Path Traversal vulnerability in Exchange Online backup module.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.5",
  "pubDate": "2026-08-11T07:17:28.233Z",
  "pubdate": "2026-08-11T07:17:28.233Z",
  "executiveSummary": "An authenticated path traversal vulnerability has been identified within the Exchange Online backup module of Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus.\nThis security flaw allows an authenticated malicious actor to manipulate input parameters containing directory traversal sequences, enabling unauthorized access to arbitrary files and directories on the underlying host operating system.\nThe vulnerability directly impacts Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820.\nThe risk implications include potential disclosure of sensitive configuration files, application data, or system files depending on the privileges of the application process.\nSuccessful exploitation of this vulnerability requires the attacker to possess valid authentication credentials to the target application and network access to the vulnerable endpoint.\nOrganizations utilizing affected versions face heightened exposure to unauthorized data access and internal reconnaissance if unmitigated.",
  "technicalDetails": "The vulnerability resides within the Exchange Online backup module of Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820.\nThe root cause stems from insufficient input validation and sanitization of user-supplied parameters processed by the backup module, specifically failing to properly neutralize directory traversal sequences such as dot-dot-slash (..\\ or ../).\nTo exploit this vulnerability, an attacker must first authenticate to the application with valid user credentials, satisfying the initial access control requirements.\nThe attacker then crafts a malicious HTTP request directed at the vulnerable Exchange Online backup module endpoint, injecting path traversal sequences into the vulnerable parameter.\nUpon receiving the request, the application fails to validate the boundaries of the targeted file path, resolving the traversal sequences relative to the application root or system root directory.\nThis flawed logic permits the application to read and return the contents of arbitrary files residing outside the intended operational directory, constrained only by the file system permissions of the service account executing the application.\nThe attack flow proceeds as follows: 1) Authentication against the target M365 Manager Plus or M365 Security Plus instance, 2) Crafting an HTTP request containing malicious path traversal payloads targeting the Exchange Online backup functionality, 3) Transmission of the payload over the network to the application server, 4) Improper handling and resolution of the file path by the vulnerable component, and 5) Retrieval of unauthorized file contents in the application response.\nThe vulnerability requires network exposure of the management interface, valid authentication credentials, and targets specific backend file retrieval routines within the Exchange Online backup component."
}
CVE-2026-16053: ManageEngine M365 Path Traversal (HIGH Severity, CVSS: 8.5) - Sceawere