Improper access control in ManageEngine DDI Central - CVE-2026-12264
Published: August 15, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper access control in the HA Failover Config sync upload workflow when handling archive uploads. A remote user can upload a specially crafted archive containing unsafe file paths to execute arbitrary code.
Exploitation can result in file writes to restricted application paths and may lead to code execution as root.