Sceawere
Vulnerability Detail
CVE-2026-12265UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
ManageEngine DDI Central Access Control
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 3h ago
- Vendor
- Zohocorp
- Product
- DDI Central
- Attack Type
- N/A
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Insufficient access control in HA failover endpoint leading to destructive PostgreSQL database operations.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-09-28T13:17:21.550Z",
"pubdate": "2026-09-28T13:17:21.550Z",
"executiveSummary": "ManageEngine DDI Central versions prior to 6201 contain a critical insufficient access control vulnerability within the High Availability (HA) failover endpoint.\nThis flaw allows an unauthenticated or unauthorized actor to interact with administrative API endpoints, specifically those governing PostgreSQL database operations.\nThe vulnerability poses a severe risk to data integrity and system availability, as exploitation enables the execution of destructive database commands.\nThe impact includes potential data loss, corruption of system configuration tables, and catastrophic service failure due to the nature of the exposed PostgreSQL management functions.\nThe vulnerability is situated in the HA failover communication mechanism, which fails to adequately validate the identity or authorization level of the request initiator before processing commands.\nThere are no complex exploitation requirements mentioned beyond network reachability to the vulnerable endpoint. Given the nature of database-level operations, this is classified as a high-severity security defect requiring immediate attention.",
"technicalDetails": "The root cause of this vulnerability is improper authorization enforcement within the High Availability (HA) failover logic of ManageEngine DDI Central. Specifically, the application exposes an internal API endpoint responsible for managing HA state transitions and database synchronization tasks.\nThe vulnerability stems from the application's failure to verify the authenticity or the administrative privilege level of incoming requests targeting this specific HA failover endpoint. Under normal operational conditions, this endpoint is intended to facilitate seamless failover between primary and secondary nodes; however, the lack of access controls allows an attacker to interact with the underlying PostgreSQL database management interface.\nThe attack flow involves the adversary sending crafted requests to the vulnerable HA failover endpoint. Because the endpoint does not enforce proper session or credential validation, it treats the incoming packet as a legitimate system-level command. When processed, these commands are passed to the backend PostgreSQL environment.\nExploitation involves the injection of SQL commands or administrative database operational triggers through the failover endpoint's parameters. Since the system expects these requests to originate from an trusted internal high-availability heartbeat, the input is processed with elevated privileges, allowing the execution of arbitrary database operations.\nThe destructive capability arises from the ability to invoke functions that can drop tables, modify schema constraints, or truncate essential configuration data stored within the PostgreSQL instance. By manipulating these backend structures, an attacker can effectively disable the DDI Central service or manipulate network resource allocations managed by the software.\nThe vulnerability affects all versions of ManageEngine DDI Central prior to 6201. The component affected is the HA management subsystem, which is typically reachable over the management network. As the vulnerability resides at the API interaction layer, it does not necessarily require a valid administrative session, provided the attacker can communicate with the service endpoint responsible for HA signaling. The post-exploitation impact is critical, as it bypasses application-level security and directly compromises the persistence and integrity layer of the product."
}