CVE-2026-6516

Zohocorp · ManageEngine ADAudit Plus

ManageEngine ADAudit Plus is vulnerable to unauthenticated remote code execution due to a flaw in the agent API, which fails to properly neutralize OS commands.

Executive summary

A critical unauthenticated remote code execution vulnerability in ManageEngine ADAudit Plus enables attackers to execute arbitrary system commands.

Vulnerability

The vulnerability is categorized as an OS command injection flaw located within the agent API. It allows unauthenticated attackers to send specially crafted requests that result in the execution of arbitrary commands on the host server.

Business impact

A successful exploit provides the attacker with full control over the server hosting ADAudit Plus. Because ADAudit Plus typically operates with elevated privileges to monitor Active Directory environments, this compromise could lead to lateral movement within the network, theft of sensitive credentials, and complete domain compromise. The CVSS score of 10.0 highlights the maximum severity of this vulnerability.

Remediation

Immediate Action: Update ManageEngine ADAudit Plus to build 8606 or higher immediately.

Proactive Monitoring: Monitor server logs for suspicious child processes or unauthorized shell executions originating from the ADAudit Plus service account.

Compensating Controls: Use a network firewall to restrict access to the ADAudit Plus management interface and agent API to trusted internal IP addresses only.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This is a critical vulnerability that requires immediate remediation. All instances of ManageEngine ADAudit Plus must be updated to the latest version to prevent potential remote code execution. Security teams should prioritize this update as part of their urgent patch management lifecycle.