Command injection in ManageEngine DDI Central - CVE-2026-12267
Published: August 15, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to command injection in the Windows DNS Query Resolution Policy name field when processing user-supplied policy names for Windows DNS server operations. A remote user can supply a crafted policy name to execute arbitrary code.
Exploitation results in unsafe PowerShell commands being executed on a managed Windows DNS server.