Sceawere
Vulnerability Detail
CVE-2026-12269UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
ManageEngine DDI Central Configuration Injection
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 3h ago
- Vendor
- Zohocorp
- Product
- DDI Central
- Attack Type
- CWE-434 Unrestricted upload of file with dangerous type
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Zohocorp ManageEngine DDI Central 6.2.0 build below 6201 had a Keepalived configuration injection vulnerability in the HA configuration workflow. This issue could allow an authenticated operator-level user to modify the Keepalived configuration and potentially execute commands as root on the DDI Central host.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-09-28T11:16:44.177Z",
"pubdate": "2026-09-28T11:16:44.177Z",
"executiveSummary": "ManageEngine DDI Central versions 6.2.0 prior to build 6201 are susceptible to a configuration injection vulnerability within the High Availability (HA) workflow. This flaw allows an authenticated operator-level user to perform unauthorized modifications to the Keepalived service configuration files.\nThe vulnerability represents a significant security risk, as successful exploitation enables the execution of arbitrary commands with root-level privileges on the host operating system. By manipulating the parameters passed to the Keepalived configuration, an attacker can leverage system-level functionalities to achieve code execution.\nThe attack vector requires the adversary to possess valid operator-level credentials, limiting exploitation to internal actors or compromised accounts. Given the sensitive nature of DDI Central as a core network infrastructure component, this vulnerability poses a critical threat to system integrity, confidentiality, and availability, potentially leading to full administrative compromise of the underlying host.",
"technicalDetails": "The vulnerability resides within the High Availability (HA) management module of ManageEngine DDI Central. The application fails to adequately sanitize user-supplied input during the processing of Keepalived configuration parameters. Keepalived, which relies on configuration files to define virtual routing redundancy protocols and health checking, executes scripts or commands defined within these files as part of its operational cycle.\nThe root cause is an improper neutralization of special elements used in command execution (CWE-78/CWE-88 equivalents) during the HA configuration workflow. Because the application processes these inputs and writes them directly to sensitive configuration files (e.g., keepalived.conf), an operator-level user can inject arbitrary directives or script hooks that are subsequently interpreted by the Keepalived service upon service restart or state transition.\nThe attack flow follows a structured path: First, an attacker authenticates to the DDI Central management interface with operator-level permissions. Second, the attacker navigates to the HA configuration module. Third, the attacker inputs malicious directives into the input fields intended for Keepalived parameters. Because the application logic lacks server-side validation or parameterized configuration handling, the input is written directly into the persistent configuration file.\nOnce the injected configuration is saved, the attacker forces or waits for a configuration reload or a service restart. When Keepalived processes the modified configuration, it executes the injected commands with the privileges of the Keepalived process, which typically operates under root context on the DDI Central host. This results in arbitrary code execution.\nPost-exploitation impact is severe, granting the attacker root access to the DDI Central host. This access allows for full control over the appliance, including the ability to exfiltrate database contents, manipulate network configurations, install persistent backdoors, or pivot into the internal network segment. The exposure is limited to authenticated users, necessitating the monitoring of internal access logs and privilege escalation patterns for defensive detection."
}