CVE-2026-16053: Path Traversal
Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to Authenticated Path Traversal vulnerability in Exchange Online backup module.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ManageEngine M365 Manager Plus / M365 Security Plusto a version that resolves this vulnerability.Fixed in 4820
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16053?
The severity of CVE-2026-16053 is rated high, with a score of 8.5.
What kind of vulnerability is CVE-2026-16053?
CVE-2026-16053 is an Authenticated Path Traversal vulnerability affecting the Exchange Online backup module.
Which versions are affected by CVE-2026-16053?
CVE-2026-16053 affects Zoho ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820.
How do I fix CVE-2026-16053?
To fix CVE-2026-16053, upgrade to Zoho ManageEngine M365 Manager Plus or M365 Security Plus version 4820 or later.
What are the potential impacts of CVE-2026-16053?
The impacts of CVE-2026-16053 include unauthorized access to sensitive data due to path traversal in the application.