Improper access control in ManageEngine DDI Central - CVE-2026-12266

 

Improper access control in ManageEngine DDI Central - CVE-2026-12266

Published: August 15, 2026


Vulnerability identifier: #VU142609
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-12266
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper access control in the LDAP settings API when handling authenticated settings retrieval requests. A remote user can request LDAP authentication configuration details to disclose sensitive information.

The exposed information may include the LDAP bind password and related authentication configuration details.


Affected software

ManageEngine DDI Central

How to mitigate CVE-2026-12266

Install security update from vendor's website.

ManageEngine DDI Central - update to 6201

External References

Related Security Bulletins