Sceawere
Vulnerability Detail
CVE-2026-12268UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
ManageEngine DDI Central RCE
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 3h ago
- Vendor
- Zohocorp
- Product
- DDI Central
- Attack Type
- CWE-20 Improper input validation
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
ManageEngine DDI Central versions below 6201 are vulnerable to PowerShell command injection in Windows DNS SPF/TXT record push leading to remote code execution.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-09-28T11:16:44.063Z",
"pubdate": "2026-09-28T11:16:44.063Z",
"executiveSummary": "ManageEngine DDI Central versions prior to 6201 are susceptible to a critical PowerShell command injection vulnerability.\nThe flaw exists within the Windows DNS SPF/TXT record push functionality, allowing unauthenticated or authorized attackers to execute arbitrary commands with elevated system privileges.\nThis vulnerability is classified as a remote code execution (RCE) flaw, posing a severe risk to the confidentiality, integrity, and availability of the affected DDI (DNS, DHCP, and IPAM) infrastructure.\nSuccessful exploitation enables an attacker to gain full control over the underlying Windows server hosting the DDI Central instance.\nThe attack is characterized by the improper sanitization of user-supplied inputs destined for PowerShell execution contexts, enabling the injection of malicious command strings.\nGiven the nature of DDI environments, which often interface directly with core network services, this vulnerability provides a significant vector for lateral movement and complete system compromise within a corporate network.",
"technicalDetails": "The vulnerability resides in the backend processing logic of the Windows DNS SPF and TXT record management module within ManageEngine DDI Central. The root cause is the failure to adequately sanitize user-controllable input fields during the record push operation before these strings are passed to a PowerShell execution environment.\nIn a standard deployment, when an administrator or user attempts to push DNS SPF or TXT records, the application backend constructs a PowerShell command line intended to interact with the Windows DNS server configuration. The vulnerable component fails to perform sufficient input validation or employ parameterization, effectively concatenating user-provided record data directly into the command execution string.\nAn attacker can exploit this by crafting a malicious payload within the SPF or TXT record fields. By incorporating command separators such as ';', '&', or '|' followed by arbitrary PowerShell instructions, the attacker can break out of the intended command context. Upon the submission of the update request, the server-side process executes the injected malicious instructions.\nThe execution context of the injected commands is governed by the service account under which the DDI Central service is running, which is typically configured with high-level administrative privileges on the Windows host to manage DNS server settings. Consequently, the payload executes with the privileges required to modify system-level configurations, install backdoors, or exfiltrate sensitive data from the network environment.\nAttack Flow: 1. The attacker crafts a request containing an injected PowerShell command payload within an SPF or TXT record update field. 2. The DDI Central application processes this request and calls a backend PowerShell script responsible for updating the Windows DNS records. 3. Due to the lack of sanitization, the application treats the malicious input as part of the executable script. 4. The underlying Windows OS executes the injected PowerShell command with the privileges of the DDI Central service. 5. The attacker successfully gains remote code execution on the target server.\nThis flaw is particularly severe as it bypasses standard application-level controls, leveraging the legitimate administrative functionality of the DDI platform to weaponize system-level commands. Because the vulnerability involves the core administrative workflow of the product, it is difficult to detect through traditional endpoint monitoring that expects legitimate PowerShell activity originating from the DDI service."
}