Threat Advisory

ManageEngine ADAudit Plus Flaw Enables Unauthenticated Remote Code Execution

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A critical vulnerability affecting ADAudit Plus versions and patching, tracked as CVE-2026-6516 with a CVSS score of 10.0, enables unauthenticated remote code execution on Active Directory audit servers by exploiting two weaknesses in the product's Agent APIs, an authentication bypass and a path traversal, chaining into unauthenticated remote code execution. This flaw affects all versions below build 8606, which carries the fix released on 17 April 2026. ADAudit Plus watches Active Directory for a living, running agents on domain controllers, file servers, and workstations, placing an attacker right beside the directory it monitors if compromised. The business impact of this vulnerability is significant, as it allows an unauthenticated adversary to potentially achieve remote code execution, which can lead to severe consequences such as data breaches, system compromise, and unauthorized access to sensitive information.

RECOMMENDATION:

We recommend you to update ADAudit Plus to version 8606.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A critical vulnerability affecting ADAudit Plus versions and patching, tracked as CVE-2026-6516 with a CVSS score of 10.0, enables unauthenticated remote code execution on Active Directory audit servers by exploiting two weaknesses in the product's Agent APIs, an authentication bypass and a path traversal, chaining into unauthenticated remote code execution. This flaw affects all versions below build 8606, which carries the fix released on 17 April 2026. ADAudit Plus watches Active Directory for a living, running agents on domain controllers, file servers, and workstations, placing an attacker right beside the directory it monitors if compromised. The business impact of this vulnerability is significant, as it allows an unauthenticated adversary to potentially achieve remote code execution, which can lead to severe consequences such as data breaches, system compromise, and unauthorized access to sensitive information.

RECOMMENDATION:

We recommend you to update ADAudit Plus to version 8606.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu