Junglewise Threat Intelligence

CVE-2026-12571: ManageEngine DDI Central authentication bypass in password-reset

CVE-2026-12571 · Severity: critical · CVSS 9.8 · Published 2026-08-11

Vendors: ManageEngine.

Executive brief

ManageEngine DDI Central is a DNS, DHCP, and IP address management platform used by organizations to manage critical network infrastructure. An authentication bypass flaw in the password-reset workflow allows attackers to take over administrator accounts without valid credentials, leading to complete compromise of the network management system and potential unauthorized changes to DNS and DHCP configurations.

Technical details

An authentication bypass exists in DDI Central's password-reset verification workflow that fails to properly validate reset requests, allowing an attacker to reset any user's password and gain account access without possessing the original credentials. The vulnerability is exploitable remotely and does not require prior authentication or user interaction. An attacker can leverage a compromised administrative account to modify DNS zones, DHCP pools, and network configurations across managed infrastructure. The issue was fixed in Build 6201.

Affected products

  • ManageEngine DDI Central before Build 6201

Timeline

  • 2026-08-11: disclosed

References