CVE-2026-12571

Summary

An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover.

Affected Software

VendorProductVersion RangeStatus
zohocorpmanageengine_ddi_central0 < 6201affected

Weaknesses

  • CWE-287: CWE-287 Improper Authentication
  • CWE-640: CWE-640 Weak Password Recovery Mechanism for Forgotten Password

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: total

References