CVE-2026-12571: Authentication Bypass Leading to Account Takeover
Published Aug 11, 2026
·Updated
An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover.
Affected Software
1 affected component
ManageEngine DDI Central
Event History
Aug 11, 2026
CVE Published
via MITRE·04:52 PM
Data Sourced
via MITRE·04:52 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-12571?
CVE-2026-12571 has a critical severity rating of 9.8.
2
What type of vulnerability is CVE-2026-12571?
CVE-2026-12571 is an authentication bypass vulnerability that can lead to account takeover.
3
How does CVE-2026-12571 affect ManageEngine DDI Central?
CVE-2026-12571 allows attackers to bypass authentication in the password-reset workflow, enabling unauthorized access to accounts.
4
How do I fix CVE-2026-12571?
To fix CVE-2026-12571, ensure that you update ManageEngine DDI Central to the latest version that addresses this vulnerability.
5
What is the potential impact of CVE-2026-12571?
The potential impact of CVE-2026-12571 includes unauthorized access to user accounts, leading to data exposure and user impersonation.