cbcvebase.

Zohocorp Ddi Central vulnerabilities

5 known vulnerabilities affecting zohocorp/ddi_central.

Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH5

Vulnerabilities

Page 1 of 1
CVE-2026-12268P2HIGHCVSS 8.8fixed in 62012026-09-28
CVE-2026-12268 [HIGH] CWE-20 CVE-2026-12268: ManageEngine DDI Central versions below 6201 are vulnerable to PowerShell command injection in Windo ManageEngine DDI Central versions below 6201 are vulnerable to PowerShell command injection in Windows DNS SPF/TXT record push leading to remote code execution.
nvd
CVE-2026-12264P2HIGHCVSS 8.8fixed in 62012026-09-28
CVE-2026-12264 [HIGH] CWE-434 CVE-2026-12264: Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Arbitrary file write via HA Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Arbitrary file write via HA Failover Config sync upload leading to remote code execution.
nvd
CVE-2026-12269P2HIGHCVSS 8.8fixed in 62012026-09-28
CVE-2026-12269 [HIGH] CWE-269 CVE-2026-12269: Zohocorp ManageEngine DDI Central 6.2.0 build below 6201 had a Keepalived configuration injection vu Zohocorp ManageEngine DDI Central 6.2.0 build below 6201 had a Keepalived configuration injection vulnerability in the HA configuration workflow. This issue could allow an authenticated operator-level user to modify the Keepalived configuration and potentially execute commands as root on the DDI Central host.
nvd
CVE-2026-12265P3HIGHCVSS 8.8fixed in 62012026-09-28
CVE-2026-12265 [HIGH] CWE-284 CVE-2026-12265: Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Insufficient access control Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Insufficient access control in HA failover endpoint leading to destructive PostgreSQL database operations.
nvd
CVE-2026-12267P3HIGHCVSS 7.2fixed in 62012026-09-28
CVE-2026-12267 [HIGH] CWE-20 CVE-2026-12267: ManageEngine DDI Central versions below 6201 are vulnerable to Command injection in Windows DNS Quer ManageEngine DDI Central versions below 6201 are vulnerable to Command injection in Windows DNS Query Resolution Policy name field leading to remote code execution.
nvd
Zohocorp Ddi Central vulnerabilities | cvebase