SQL injection in ManageEngine DDI Central - CVE-2026-12572

 

SQL injection in ManageEngine DDI Central - CVE-2026-12572

Published: August 15, 2026


Vulnerability identifier: #VU142617
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-12572
CWE-ID: CWE-89
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute commands as the PostgreSQL service account.

The vulnerability exists due to SQL injection in the HA replication user configuration workflow when handling replication username input. A remote user can inject crafted SQL through the replication username field to execute commands as the PostgreSQL service account.

Exploitation requires administrative access to the application.


Affected software

ManageEngine DDI Central

How to mitigate CVE-2026-12572

Install security update from vendor's website.

ManageEngine DDI Central - update to 6201

External References

Related Security Bulletins