Security Updates - CVE Database

List of security vulnerabilities fixed in DDI Central

This page lists security vulnerability fixes made in various releases of DDI Central and vulnerability details. Go to ManageEngine's Security Response Center to report vulnerabilities on ManageEngine products.

To receive security advisories for DDI Central, subscribe here

 
CVE / ZVE IDSynopsisSeverityFixed in version
CVE-2024-27311Arbitrary file writing via directory traversalMediumBuild 4002
CVE-2024-5471Unrestricted takeover of Node Agent serversHighBuild 4002
CVE-2024-12686Remote command execution on Node Agent/DDI Console serversMediumBuild 4002
CVE-2026-12265Insufficient access control in HA failover endpoint leading to destructive PostgreSQL database operationsHighBuild 6201
CVE-2026-12266LDAP bind password exposure through insufficiently protected LDAP settings APIHighBuild 6201
CVE-2026-12267Command injection in Windows DNS Query Resolution Policy name field leading to remote code executionHighBuild 6201
CVE-2026-12268PowerShell command injection in Windows DNS SPF/TXT record push leading to remote code executionHighBuild 6201
CVE-2026-12264Arbitrary file write via HA Failover Config sync upload leading to remote code execution as rootHighBuild 6201
CVE-2026-12269Keepalived configuration injection through HA workflow leading to remote code execution as rootHighBuild 6201
CVE-2026-12571Authentication bypass in password-reset verification workflow leading to account takeoverHighBuild 6201
CVE-2026-12574Server-side HTML/JavaScript injection in analytics PDF generation leading to local file disclosureHighBuild 6201
CVE-2026-12573Cisco IOS command injection via DHCP pool name leading to arbitrary commands on managed Cisco routersHighBuild 6201
CVE-2026-12572SQL injection in HA replication username handling leading to command execution as the PostgreSQL service accountHighBuild 6201