CVE-2026-12268: Authenticated PowerShell Injection leads to RCE
ManageEngine DDI Central versions below 6201 are vulnerable to PowerShell command injection in Windows DNS SPF/TXT record push leading to remote code execution.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ManageEngine DDI Centralto a version that resolves this vulnerability.Fixed in 6201
Event History
Frequently Asked Questions
Which deployments are affected?
ManageEngine DDI Central versions below 6201 are affected when using the Windows DNS SPF/TXT record push functionality.
What level of access does an attacker need?
The vulnerability requires authenticated access with low privileges. No user interaction is required, and exploitation can result in remote code execution with confidentiality, integrity, and availability impact.
What is the recommended remediation?
Upgrade ManageEngine DDI Central to version 6201 or later. If an immediate upgrade is not possible, restrict access to authenticated users who do not need Windows DNS SPF/TXT record push capabilities.