Security Updates - CVE Database

CVE-2026-19419

Authenticated DHCP configuration injection leading to remote command execution fixed in build 6301

Severity: Critical

CVE ID: CVE-2026-19419

Affected Software Version(s): DDI Central build 6300 and below

Fixed Version: Build 6301

Fixed on: August 04, 2026

Details:

ManageEngine DDI Central build 6300 had a DHCP configuration injection vulnerability in the processing of user-supplied DHCP client-class conditions.

The affected fields were inserted into the generated ISC DHCP configuration without sufficient validation of DHCP configuration directives and control characters. An authenticated user with permission to manage DHCP configurations could submit a specially crafted client-class condition containing ISC DHCP statements such as execute().

When the generated configuration was applied to a managed ISC DHCP server, the injected statement could be executed by the DHCP service when a lease event occurred. Because the DHCP service could run with elevated operating-system privileges, successful exploitation could result in arbitrary command execution as root on the managed DHCP server.

The vulnerability has been fixed by introducing stricter validation for values included in generated DHCP configuration files. Dangerous ISC DHCP directives and keywords, including command-execution statements such as execute, are now rejected before the configuration is generated or applied. Inputs containing restricted DHCP statements or injection patterns are blocked, preventing user-supplied values from being interpreted as executable DHCP configuration directives.

Impact:

Successful exploitation of this vulnerability could allow an authenticated user with DHCP management permissions to execute arbitrary operating-system commands with the privileges of the DHCP service.

Where the DHCP service runs as root, this could result in complete compromise of the managed DHCP server, including unauthorized access to DNS and DHCP configurations, modification of network services, disclosure of sensitive information, service disruption, and further movement within the managed network.

Steps to upgrade:

Update your DDI Central installation to the latest build 6301 using the applicable service pack.

After completing the upgrade, verify that the DDI Central Console and all applicable Node Agent or managed DHCP server components are running the recommended versions.

Acknowledgements:

This issue was reported by qquynh.