CVE-2026-16053
8.5Zohocorp · ManageEngine M365 Manager Plus and M365 Security Plus
ManageEngine M365 Manager Plus and Security Plus are affected by an authenticated path traversal vulnerability in the Exchange Online backup module.
Executive summary
ManageEngine M365 Manager Plus and Security Plus are vulnerable to an authenticated path traversal flaw that allows authorized users to perform unauthorized file operations.
Vulnerability
This is a relative path traversal vulnerability (CWE-23) within the Exchange Online backup module, requiring an authenticated user to exploit the flaw.
Business impact
With a CVSS score of 8.5, this vulnerability presents a significant risk to organizational security, as it allows an authenticated user to bypass file restrictions and potentially impact system availability or data integrity. The ability to manipulate system paths through the backup module could be leveraged for privilege escalation or lateral movement within the M365 management environment.
Remediation
Immediate Action: Update both ManageEngine M365 Manager Plus and M365 Security Plus to build 4820 or higher to remediate the vulnerability.
Proactive Monitoring: Review audit logs for unusual activity involving the Exchange Online backup module and monitor for attempts to access unexpected file paths by authenticated users.
Compensating Controls: Limit access to the administrative console of M365 Manager/Security Plus to trusted personnel only and enforce the principle of least privilege to minimize the risk of compromised accounts.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Administrators should treat this as a high priority update given the 8.5 CVSS score and the critical nature of the affected software. Applying the update to version 4820 is the only definitive way to mitigate the risk of path traversal within the backup module.