Sceawere
Vulnerability Detail
CVE-2026-16053UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
ManageEngine M365 Path Traversal
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.5
- Creation Date
- 3h ago
- Vendor
- Zohocorp
- Product
- ManageEngine M365 Manager Plus
- Attack Type
- CWE-23 Relative path traversal
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to Authenticated Path Traversal vulnerability in Exchange Online backup module.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.5",
"pubDate": "2026-08-11T07:17:28.233Z",
"pubdate": "2026-08-11T07:17:28.233Z",
"executiveSummary": "An authenticated path traversal vulnerability has been identified within the Exchange Online backup module of Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus.\nThis security flaw allows an authenticated malicious actor to manipulate input parameters containing directory traversal sequences, enabling unauthorized access to arbitrary files and directories on the underlying host operating system.\nThe vulnerability directly impacts Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820.\nThe risk implications include potential disclosure of sensitive configuration files, application data, or system files depending on the privileges of the application process.\nSuccessful exploitation of this vulnerability requires the attacker to possess valid authentication credentials to the target application and network access to the vulnerable endpoint.\nOrganizations utilizing affected versions face heightened exposure to unauthorized data access and internal reconnaissance if unmitigated.",
"technicalDetails": "The vulnerability resides within the Exchange Online backup module of Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820.\nThe root cause stems from insufficient input validation and sanitization of user-supplied parameters processed by the backup module, specifically failing to properly neutralize directory traversal sequences such as dot-dot-slash (..\\ or ../).\nTo exploit this vulnerability, an attacker must first authenticate to the application with valid user credentials, satisfying the initial access control requirements.\nThe attacker then crafts a malicious HTTP request directed at the vulnerable Exchange Online backup module endpoint, injecting path traversal sequences into the vulnerable parameter.\nUpon receiving the request, the application fails to validate the boundaries of the targeted file path, resolving the traversal sequences relative to the application root or system root directory.\nThis flawed logic permits the application to read and return the contents of arbitrary files residing outside the intended operational directory, constrained only by the file system permissions of the service account executing the application.\nThe attack flow proceeds as follows: 1) Authentication against the target M365 Manager Plus or M365 Security Plus instance, 2) Crafting an HTTP request containing malicious path traversal payloads targeting the Exchange Online backup functionality, 3) Transmission of the payload over the network to the application server, 4) Improper handling and resolution of the file path by the vulnerable component, and 5) Retrieval of unauthorized file contents in the application response.\nThe vulnerability requires network exposure of the management interface, valid authentication credentials, and targets specific backend file retrieval routines within the Exchange Online backup component."
}