Authenticated Path Traversal Vulnerability in ManageEngine M365 Manager Plus and M365 Security Plus
CVE-2026-16053

8.5HIGH

What is CVE-2026-16053?

The ManageEngine M365 Manager Plus and M365 Security Plus software by Zohocorp suffers from an Authenticated Path Traversal vulnerability in its Exchange Online backup module. This vulnerability allows an attacker with valid credentials to access restricted file paths and retrieve sensitive information from the system, posing significant security risks for data confidentiality.

Affected Version(s)

ManageEngine M365 Manager Plus 0 < 4820

ManageEngine M365 Security Plus 0 < 4820

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.