Improper access control in ManageEngine DDI Central - CVE-2026-12266
Published: August 15, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the LDAP settings API when handling authenticated settings retrieval requests. A remote user can request LDAP authentication configuration details to disclose sensitive information.
The exposed information may include the LDAP bind password and related authentication configuration details.