ManageEngine ADAudit Plus Pre-Authentication Remote Code Execution Vulnerability
CVE-2026-6516 is a critical pre-authentication vulnerability affecting ManageEngine ADAudit Plus. The vulnerability exists within the product’s Agent APIs and involves authentication bypass and path traversal weaknesses that could allow an unauthenticated attacker to write files outside their intended directory. Successful exploitation may ultimately lead to remote code execution. The vulnerability affects ADAudit Plus builds prior to 8606 and has been assigned a CVSS v3.1 score of 10.0 (Critical). At the time of publication, there are no confirmed reports of active exploitation in the wild.
Technical Details
ManageEngine ADAudit Plus is an Active Directory auditing and reporting solution used to monitor user activity, administrative actions, and security events across Windows Active Directory environments.
CVE-2026-6516 affects the product’s Agent APIs. The vulnerability involves authentication bypass and path traversal weaknesses that can be exploited remotely without authentication or user interaction. An attacker can leverage these flaws to write files outside their intended directory, potentially resulting in remote code execution.
The vulnerability has a CVSS v3.1 vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L, reflecting network-based exploitation with low attack complexity and no required privileges.
NodeZero® Proactive Security Platform — Rapid Response
A NodeZero Rapid Response test has been developed to safely validate whether CVE-2026-6516 can be exploited in your environment. The test executes real attack techniques without causing damage, giving security teams immediate clarity on exposure.
- Run the Rapid Response test: Launch the test from the NodeZero platform to determine whether your ADAudit Plus instance is vulnerable.
- Patch immediately: Upgrade ADAudit Plus to build 8606 and update affected Windows and macOS agents in accordance with ManageEngine guidance.
- Re-run the test: Verify that the vulnerability is no longer exploitable after remediation.
Affected Versions & Patch
Affected
- ManageEngine ADAudit Plus builds earlier than 8606.
Fixed
- ManageEngine ADAudit Plus Build 8606.
Mitigations
ManageEngine recommends:
- Upgrade ADAudit Plus to Build 8606 using the latest service pack.
- Upgrade Windows agents running versions earlier than 7060.
- Upgrade all installed macOS agents to the latest available version.
- Verify agent versions from Configuration → Agent Management → Manage → Installed Version within the ADAudit Plus console.
Timeline
- April 17, 2026: ManageEngine released ADAudit Plus Build 8606, which addresses CVE-2026-6516.
- July 23, 2026: ManageEngine published its security advisory for CVE-2026-6516.
- July 23, 2026: CVE-2026-6516 was published in the CVE Program.
- July 24, 2026: NIST published the CVE in the National Vulnerability Database with CVSS scoring.
- July 28, 2026: Horizon3.ai released a NodeZero Rapid Response test for CVE-2026-6516.