Zohocorp Ddi Central vulnerabilities
5 known vulnerabilities affecting zohocorp/ddi_central.
Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH5
Vulnerabilities
Page 1 of 1
CVE-2026-12268P2HIGHCVSS 8.8fixed in 62012026-09-28
CVE-2026-12268 [HIGH] CWE-20 CVE-2026-12268: ManageEngine DDI Central versions below 6201 are vulnerable to PowerShell command injection in Windo
ManageEngine DDI Central versions below 6201 are vulnerable to PowerShell command injection in Windows DNS SPF/TXT record push leading to remote code execution.
nvd
CVE-2026-12264P2HIGHCVSS 8.8fixed in 62012026-09-28
CVE-2026-12264 [HIGH] CWE-434 CVE-2026-12264: Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Arbitrary file write via HA
Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Arbitrary file write via HA Failover Config sync upload leading to remote code execution.
nvd
CVE-2026-12269P2HIGHCVSS 8.8fixed in 62012026-09-28
CVE-2026-12269 [HIGH] CWE-269 CVE-2026-12269: Zohocorp ManageEngine DDI Central 6.2.0 build below 6201 had a Keepalived configuration injection vu
Zohocorp ManageEngine DDI Central 6.2.0 build below 6201 had a Keepalived configuration injection vulnerability in the HA configuration workflow. This issue could allow an authenticated operator-level user to modify the Keepalived configuration and potentially execute commands as root on the DDI Central host.
nvd
CVE-2026-12265P3HIGHCVSS 8.8fixed in 62012026-09-28
CVE-2026-12265 [HIGH] CWE-284 CVE-2026-12265: Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Insufficient access control
Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Insufficient access control in HA failover endpoint leading to destructive PostgreSQL database operations.
nvd
CVE-2026-12267P3HIGHCVSS 7.2fixed in 62012026-09-28
CVE-2026-12267 [HIGH] CWE-20 CVE-2026-12267: ManageEngine DDI Central versions below 6201 are vulnerable to Command injection in Windows DNS Quer
ManageEngine DDI Central versions below 6201 are vulnerable to Command injection in Windows DNS Query Resolution Policy name field leading to remote code execution.
nvd