Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to Authenticated Path Traversal vulnerability in Excha...
Description
Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to Authenticated Path Traversal vulnerability in Exchange Online backup module
AI Analyst Comment
Remediation
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
---METADATA---
VENDOR: Zohocorp
PRODUCT: ManageEngine M365 Manager Plus and M365 Security Plus
AFFECTED_VERSIONS: 0 up to (excluding) 4820
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
ManageEngine M365 Manager Plus and Security Plus are affected by an authenticated path traversal vulnerability in the Exchange Online backup module.
Executive Summary:
ManageEngine M365 Manager Plus and Security Plus are vulnerable to an authenticated path traversal flaw that allows authorized users to perform unauthorized file operations.
Vulnerability Details
CVE-ID: CVE-2026-16053
Affected Software: Zohocorp ManageEngine M365 Manager Plus, M365 Security Plus
Affected Versions: 0 up to (excluding) 4820
Vulnerability: This is a relative path traversal vulnerability (CWE-23) within the Exchange Online backup module, requiring an authenticated user to exploit the flaw.
Business Impact
With a CVSS score of 8.5, this vulnerability presents a significant risk to organizational security, as it allows an authenticated user to bypass file restrictions and potentially impact system availability or data integrity. The ability to manipulate system paths through the backup module could be leveraged for privilege escalation or lateral movement within the M365 management environment.
Remediation Plan
Immediate Action: Update both ManageEngine M365 Manager Plus and M365 Security Plus to build 4820 or higher to remediate the vulnerability.
Proactive Monitoring: Review audit logs for unusual activity involving the Exchange Online backup module and monitor for attempts to access unexpected file paths by authenticated users.
Compensating Controls: Limit access to the administrative console of M365 Manager/Security Plus to trusted personnel only and enforce the principle of least privilege to minimize the risk of compromised accounts.
Exploitation Status
Public Exploit Available: Unknown.
Analyst Notes: As of August 11, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. While the vulnerability requires authentication, the high CVSS score highlights the potential for significant impact to managed M365 environments.
Analyst Recommendation
Administrators should treat this as a high priority update given the 8.5 CVSS score and the critical nature of the affected software. Applying the update to version 4820 is the only definitive way to mitigate the risk of path traversal within the backup module.