Sceawere
Vulnerability Detail
CVE-2026-12267UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
ManageEngine DDI Central Command Injection
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.2
- Creation Date
- 3h ago
- Vendor
- Zohocorp
- Product
- DDI Central
- Attack Type
- CWE-20 Improper input validation
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
ManageEngine DDI Central versions below 6201 are vulnerable to Command injection in Windows DNS Query Resolution Policy name field leading to remote code execution.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.2",
"pubDate": "2026-09-28T11:16:43.943Z",
"pubdate": "2026-09-28T11:16:43.943Z",
"executiveSummary": "ManageEngine DDI Central versions prior to 6201 contain a critical command injection vulnerability. The flaw exists within the Windows DNS Query Resolution Policy name field, allowing unauthenticated or authenticated attackers to inject arbitrary system commands.\nThis vulnerability is categorized as an OS Command Injection, where insufficient input sanitization allows the execution of unauthorized commands at the privilege level of the application service. The impact of successful exploitation is catastrophic, potentially leading to full system compromise, remote code execution (RCE), and complete loss of confidentiality, integrity, and availability of the affected host.\nThe vulnerability represents a high risk to organizational infrastructure, as DDI (DNS, DHCP, and IPAM) systems often reside in sensitive network segments. Exploitation enables an attacker to gain a foothold within the corporate network, facilitate lateral movement, and conduct further malicious activities. Organizations utilizing affected versions of ManageEngine DDI Central are at immediate risk and should prioritize immediate mitigation or upgrade efforts to address this command injection vector.",
"technicalDetails": "The root cause of this vulnerability lies in the improper validation and sanitization of user-supplied data provided to the Windows DNS Query Resolution Policy name field within ManageEngine DDI Central. In affected versions, the application processes this input as part of a system-level command string without employing adequate filtering or parameterization to prevent shell metacharacter injection.\nThe attack flow begins when an attacker identifies the specific input vector within the DNS Query Resolution Policy management interface. By crafting a malicious payload containing shell control characters (e.g., &, |, ;, or backticks), the attacker can terminate the intended administrative command and append arbitrary operating system commands. When the DDI Central back-end service processes the policy update, it invokes a system shell to execute the resulting string. Because the application often runs with elevated administrative or system privileges to interact with Windows DNS server management APIs, the injected commands are executed with the same level of authority.\nExploitation does not require complex binary exploitation techniques; rather, it leverages logical flaws in input handling. An attacker can interact with the vulnerable component via the web management interface. Once the payload is processed, the system command is executed immediately by the server process. If successful, the attacker gains the ability to execute arbitrary code, manipulate DNS records, exfiltrate sensitive network configuration data, or deploy persistent malware/web shells on the host server.\nPost-exploitation impact is severe, as DDI systems are typically integrated with enterprise Active Directory environments. A successful RCE event on the DDI server could lead to the compromise of domain credentials, facilitate man-in-the-middle attacks through DNS hijacking, or provide the attacker with a persistent backdoor into the internal network infrastructure. Given the critical nature of DNS services, this vulnerability represents a significant vector for targeted attacks aimed at intercepting traffic or disrupting network name resolution services entirely."
}