CVE-2026-12264: Authenticated File Write via HA Failover Config Upload leads to RCE
Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Arbitrary file write via HA Failover Config sync upload leading to remote code execution.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Zohocorp ManageEngine DDI Centralto a version that resolves this vulnerability.Fixed in 6201
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
An attacker needs authenticated access with low privileges. No user interaction is required, and the attack can be performed over the network.
Which deployments are affected?
Zohocorp ManageEngine DDI Central versions earlier than 6201 are affected. The issue is in the HA Failover Config sync upload functionality.
What is the potential impact of successful exploitation?
Successful exploitation can allow arbitrary file writes and lead to remote code execution. The reported impact includes compromise of confidentiality, integrity, and availability.