Command injection in ManageEngine DDI Central - CVE-2026-12269
Published: August 15, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code as root.
The vulnerability exists due to improper neutralization of special elements in the Keepalived configuration update workflow when handling HA configuration updates. A remote user can modify Keepalived configuration input to execute arbitrary code as root.
Exploitation requires operator-level access to the affected endpoint.