CVE-2026-12269

Summary

Zohocorp ManageEngine DDI Central 6.2.0 build below 6201 had a Keepalived configuration injection vulnerability in the HA configuration workflow. This issue could allow an authenticated operator-level user to modify the Keepalived configuration and potentially execute commands as root on the DDI Central host.

Affected Software

VendorProductVersion RangeStatus
ZohocorpDDI Central0 < 6201affected

Weaknesses

  • CWE-434: CWE-434 Unrestricted upload of file with dangerous type
  • CWE-269: CWE-269 Improper Privilege Management

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References