SQL injection in ManageEngine DDI Central - CVE-2026-12572
Published: August 15, 2026
Vulnerability details
The vulnerability allows a remote user to execute commands as the PostgreSQL service account.
The vulnerability exists due to SQL injection in the HA replication user configuration workflow when handling replication username input. A remote user can inject crafted SQL through the replication username field to execute commands as the PostgreSQL service account.
Exploitation requires administrative access to the application.