CVE-2026-12269
Received Received - Intake

Authenticated Operator-Level Keepalived Configuration Injection in Zohocorp ManageEngine DDI Central

Vulnerability report for CVE-2026-12269, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: ManageEngine

Description

Zohocorp ManageEngine DDI Central 6.2.0 build below 6201 had a Keepalived configuration injection vulnerability in the HA configuration workflow. This issue could allow an authenticated operator-level user to modify the Keepalived configuration and potentially execute commands as root on the DDI Central host.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
zohocorp manageengine_ddi_central 6.2.0
zohocorp manageengine_ddi_central to 6.2.0 (inc)
zohocorp manageengine_ddi_central From 6.2.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
CWE-269 The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-12269 is a high-severity vulnerability in Zohocorp ManageEngine DDI Central version 6.2.0 (build 6200) that allows configuration injection in the Keepalived HA workflow. An authenticated operator-level user could exploit this flaw to modify the Keepalived configuration and execute arbitrary commands as root on the DDI Central host.

Detection Guidance

Check the current build version of ManageEngine DDI Central by accessing the admin console or checking the installation directory. If the build is below 6201, the system is vulnerable. Review Keepalived configuration files for unauthorized modifications and monitor for unexpected root-level command execution.

Impact Analysis

This vulnerability could allow an attacker with operator-level access to execute arbitrary commands as root on the DDI Central host. This may lead to unauthorized configuration changes, system compromise, or remote code execution, potentially resulting in full control over the affected system.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by allowing unauthorized root-level access to the DDI Central host. Unauthorized command execution may lead to data breaches, unauthorized data access, or manipulation of critical configurations, violating confidentiality and integrity requirements under these regulations.

Mitigation Strategies

Upgrade to build 6201 or later via the official service pack provided by Zohocorp. Ensure only administrator-level users have access to HA configuration workflows. Validate and sanitize all Keepalived configuration updates to prevent injection attacks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-12269. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart