Zohocorp ManageEngine DDI Central 6.2.0 build below 6201 had a Keepalived configuration injection vulnerability in the HA configuration workflow. This issue could allow an authenticated operator-level user to modify the Keepalived configuration and potentially execute commands as root on the DDI Central host.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 28 Sep 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Zohocorp ManageEngine DDI Central 6.2.0 build below 6201 had a Keepalived configuration injection vulnerability in the HA configuration workflow. This issue could allow an authenticated operator-level user to modify the Keepalived configuration and potentially execute commands as root on the DDI Central host. | |
| Title | Authenticated File Write to RCE via keepalived in DDI Central | |
| First Time appeared |
Zohocorp
Zohocorp ddi Central |
|
| Weaknesses | CWE-269 CWE-434 |
|
| CPEs | cpe:2.3:a:zohocorp:ddi_central:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Zohocorp
Zohocorp ddi Central |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Zohocorp
Published:
Updated: 2026-09-28T10:37:52.548Z
Reserved: 2026-06-15T10:39:06.686Z
Link: CVE-2026-12269
No data.
Status : Received
Published: 2026-09-28T11:16:44.177
Modified: 2026-09-28T11:16:44.177
Link: CVE-2026-12269
No data.
OpenCVE Enrichment
No data.