CVE-2026-12265: Missing Authorization on HA Failover Config allows Complete Data Destruction
Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Insufficient access control in HA failover endpoint leading to destructive PostgreSQL database operations.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Zoho ManageEngine DDI Centralto a version that resolves this vulnerability.Fixed in 6201
Event History
Frequently Asked Questions
Which deployments are affected?
Zohocorp ManageEngine DDI Central versions before 6201 are affected. Version 6201 and later are not identified as affected by the provided information.
What access does an attacker need to exploit this issue?
The vector is network-accessible and requires low privileges. No user interaction is required, according to the supplied CVSS vector.
What could exploitation allow?
The vulnerable HA failover endpoint can permit destructive PostgreSQL database operations. The reported impact includes complete compromise of confidentiality, integrity, and availability.