CVE-2026-16053
Received Received - Intake

Authenticated Path Traversal in Zohocorp ManageEngine M365 Manager Plus

Vulnerability report for CVE-2026-16053, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-11

Assigner: ManageEngine

Description

Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to Authenticated Path Traversal vulnerability in Exchange Online backup module.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-11
Generated
2026-08-31
AI Q&A
2026-08-11
EPSS Evaluated
2026-08-30
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
zohocorp m365_manager_plus to 4820 (exc)
zohocorp m365_security_plus to 4820 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-23 The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-16053 is an authenticated path traversal vulnerability affecting Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820. It exists in the Exchange Online backup module and allows authenticated attackers to delete arbitrary files on the server.

Detection Guidance

To detect this vulnerability, check the installed version of M365 Manager Plus or M365 Security Plus. If the version is below 4820, the system is vulnerable. Use commands like 'Get-WmiObject -Class Win32_Product | Where-Object {$_.Name -like "*M365 Manager Plus*"}' on Windows or 'dpkg -l | grep m365' on Linux to verify the version.

Impact Analysis

This vulnerability can lead to data integrity loss and service unavailability. Attackers could delete critical files, disrupting operations and potentially causing downtime for affected systems.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by potentially allowing unauthorized file deletion on the server through the Exchange Online backup module. Data integrity loss and service unavailability may result in violations of data protection requirements under these regulations.

Mitigation Strategies

Update M365 Manager Plus and M365 Security Plus to version 4820 or later, which includes fixes for the path traversal vulnerability. Download the latest service packs from the official ManageEngine website and apply them immediately.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16053. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart