Description
Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to Authenticated Path Traversal vulnerability in Exchange Online backup module.
Published: 2026-08-11
Score: 8.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authenticated path traversal flaw exists in the Exchange Online backup module of ManageEngine M365 Manager Plus and M365 Security Plus. The flaw allows a logged‑in user with sufficient privileges to craft requests that resolve to files outside the intended backup directory, enabling read access to arbitrary files on the server without any additional authentication or escalation. This could lead to disclosure of sensitive configuration files, credentials, or other confidential data. The weakness is classified as CWE‑23.

Affected Systems

The vulnerability affects Zohocorp’s ManageEngine M365 Manager Plus and M365 Security Plus products for all releases with a version number less than 4820. Users should verify their installed version against this threshold.

Risk and Exploitability

The CVSS base score of 8.5 indicates high severity, and the EPSS score is not available. The vulnerability is not yet listed in the CISA KEV catalog, but the lack of a low EPSS rating does not eliminate potential exploitation risk. Attackers would need valid credentials within the target system to exploit this flaw, suggesting an internal or compromised account could be used to read sensitive files. Once the path traversal is successful, the attacker could harvest sensitive data or further pivot within the environment.

Generated by OpenCVE AI on August 11, 2026 at 08:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to version 4820 or later of M365 Manager Plus and M365 Security Plus to eliminate the flaw
  • Limit backup module access to the minimum set of privileged accounts and enforce least‑privilege principles
  • If immediate patch deployment is not possible, disable the Exchange Online backup module or isolate its environment to prevent attackers from using the path traversal path

Generated by OpenCVE AI on August 11, 2026 at 08:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 07:00:00 +0000

Type Values Removed Values Added
Description Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to Authenticated Path Traversal vulnerability in Exchange Online backup module.
Title Path Traversal
First Time appeared Zohocorp
Zohocorp manageengine M365 Manager Plus
Zohocorp manageengine M365 Security Plus
Weaknesses CWE-23
CPEs cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:*:*:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_m365_security_plus:*:*:*:*:*:*:*:*
Vendors & Products Zohocorp
Zohocorp manageengine M365 Manager Plus
Zohocorp manageengine M365 Security Plus
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H'}


Subscriptions

Zohocorp Manageengine M365 Manager Plus Manageengine M365 Security Plus
cve-icon MITRE

Status: PUBLISHED

Assigner: Zohocorp

Published:

Updated: 2026-08-11T06:36:22.533Z

Reserved: 2026-07-17T10:41:20.330Z

Link: CVE-2026-16053

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T08:30:16Z

Weaknesses
  • CWE-23

    Relative Path Traversal