PT-2026-99843 · Manageengine · Ddi Central

·

CVE-2026-12269

·

Published

2026-09-28

·

Updated

2026-10-01

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ManageEngine DDI Central versions prior to 6.2.0 build 6201
Description A configuration injection flaw exists in the High Availability (HA) configuration workflow. This issue allows an authenticated user with operator-level privileges to modify the Keepalived configuration, which may lead to the execution of arbitrary commands with root privileges on the host system.
Recommendations Update ManageEngine DDI Central to build 6201 or later.

Fix

Improper Privilege Management

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12269

Affected Products

Ddi Central