SB2026081504 - Multiple vulnerabilities in ManageEngine DDI Central



SB2026081504 - Multiple vulnerabilities in ManageEngine DDI Central

Published: August 15, 2026

Security Bulletin ID SB2026081504
CSH Severity
High
Patch available
YES
Number of vulnerabilities 10
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 10% Medium 60% Low 30%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 10 vulnerabilities.


1) Improper access control (CVE-ID: CVE-2026-12265)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 7.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to perform destructive PostgreSQL database operations.

The vulnerability exists due to improper access control in the HA failover configuration endpoint when handling failover workflow requests. A remote user can send crafted requests to trigger destructive PostgreSQL database operations.

The issue is limited to authenticated low-privilege access through the failover workflow.


2) Improper access control (CVE-ID: CVE-2026-12266)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper access control in the LDAP settings API when handling authenticated settings retrieval requests. A remote user can request LDAP authentication configuration details to disclose sensitive information.

The exposed information may include the LDAP bind password and related authentication configuration details.


3) Command injection (CVE-ID: CVE-2026-12267)

CWE-ID: CWE-77 - Command injection

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to command injection in the Windows DNS Query Resolution Policy name field when processing user-supplied policy names for Windows DNS server operations. A remote user can supply a crafted policy name to execute arbitrary code.

Exploitation results in unsafe PowerShell commands being executed on a managed Windows DNS server.


4) Command injection (CVE-ID: CVE-2026-12268)

CWE-ID: CWE-77 - Command injection

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to command injection in Windows DNS SPF/TXT record handling when performing DNS record push operations. A remote user can supply crafted SPF/TXT record input to execute arbitrary code.

Exploitation requires low-privilege authenticated access.


5) Improper access control (CVE-ID: CVE-2026-12264)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to improper access control in the HA Failover Config sync upload workflow when handling archive uploads. A remote user can upload a specially crafted archive containing unsafe file paths to execute arbitrary code.

Exploitation can result in file writes to restricted application paths and may lead to code execution as root.


6) Command injection (CVE-ID: CVE-2026-12269)

CWE-ID: CWE-77 - Command injection

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to execute arbitrary code as root.

The vulnerability exists due to improper neutralization of special elements in the Keepalived configuration update workflow when handling HA configuration updates. A remote user can modify Keepalived configuration input to execute arbitrary code as root.

Exploitation requires operator-level access to the affected endpoint.


7) Improper access control (CVE-ID: CVE-2026-12571)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to take over accounts.

The vulnerability exists due to improper access control in the password-reset verification workflow when handling password-reset confirmation requests. A remote attacker can reset an account password without a valid recovery code to take over accounts.


8) Cross-site scripting (CVE-ID: CVE-2026-12574)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to server-side HTML/JavaScript injection in the analytics PDF generation workflow when generating analytics PDF reports from user-supplied content. A remote user can inject unsafe content into generated reports to disclose sensitive information.

Exploitation requires operator-level access.


9) Command injection (CVE-ID: CVE-2026-12573)

CWE-ID: CWE-77 - Command injection

CVSSv4: 7.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to execute arbitrary commands on managed Cisco routers.

The vulnerability exists due to command injection in DHCP pool name handling when provisioning Cisco routers. A remote user can pass an unsafe DHCP pool name to execute arbitrary commands on managed Cisco routers.


10) SQL injection (CVE-ID: CVE-2026-12572)

CWE-ID: CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to execute commands as the PostgreSQL service account.

The vulnerability exists due to SQL injection in the HA replication user configuration workflow when handling replication username input. A remote user can inject crafted SQL through the replication username field to execute commands as the PostgreSQL service account.

Exploitation requires administrative access to the application.


Remediation

Install update from vendor's website.