Improper access control in ManageEngine DDI Central - CVE-2026-12264

 

Improper access control in ManageEngine DDI Central - CVE-2026-12264

Published: August 15, 2026


Vulnerability identifier: #VU142612
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-12264
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to improper access control in the HA Failover Config sync upload workflow when handling archive uploads. A remote user can upload a specially crafted archive containing unsafe file paths to execute arbitrary code.

Exploitation can result in file writes to restricted application paths and may lead to code execution as root.


Affected software

ManageEngine DDI Central

How to mitigate CVE-2026-12264

Install security update from vendor's website.

ManageEngine DDI Central - update to 6201

External References

Related Security Bulletins