CVE-2026-16053 PUBLISHED

Path Traversal

Assigner: Zohocorp
Reserved: 17.07.2026 Published: 11.08.2026 Updated: 11.08.2026

Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to Authenticated Path Traversal vulnerability in Exchange Online backup module.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H
CVSS Score: 8.5

Product Status

Vendor Zohocorp
Product ManageEngine M365 Manager Plus
Versions Default: unaffected
  • affected from 0 to 4820 (excl.)
Vendor Zohocorp
Product ManageEngine M365 Security Plus
Versions Default: unaffected
  • affected from 0 to 4820 (excl.)

References

Problem Types

  • CWE-23 Relative path traversal CWE