Improper access control in ManageEngine DDI Central - CVE-2026-12265
Published: August 15, 2026
Vulnerability details
The vulnerability allows a remote user to perform destructive PostgreSQL database operations.
The vulnerability exists due to improper access control in the HA failover configuration endpoint when handling failover workflow requests. A remote user can send crafted requests to trigger destructive PostgreSQL database operations.
The issue is limited to authenticated low-privilege access through the failover workflow.