CVE-2026-6516

Published Jul 23, 2026

Last updated a month ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-6516 describes an unauthenticated remote code execution (RCE) vulnerability found in Zohocorp ManageEngine ADAudit Plus, affecting all builds prior to 8606. This flaw resides within the product's agent API and is a result of chaining two distinct weaknesses: an authentication bypass and a path traversal vulnerability. By exploiting these combined weaknesses, a remote and unauthenticated attacker can execute arbitrary code on the ADAudit Plus server. The vendor released a fix for this vulnerability in build 8606 on April 17, 2026.

Description
Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API.
Source
0fc0942c-577d-436f-ae8e-945763c79b02
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
10
Impact score
6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
Severity
CRITICAL

Weaknesses

0fc0942c-577d-436f-ae8e-945763c79b02
CWE-78

Social media

Hype score
Not currently trending