Security Updates - CVE Database

CVE-2026-19420

Insufficient zone-level authorization in DNS APIs could allowing cross-tenant access and changes fixed in build 6301

Severity: Critical

CVE ID: CVE-2026-19420

Affected Software Version(s): DDI Central 6.3.0 and below

Fixed Version: Build 6301

Fixed on: August 05, 2026

Details:

ManageEngine DDI Central 6.3.0 build 6300 had an insufficient authorization vulnerability in certain DNS zone management APIs.

DDI Central uses zone mappings to restrict non-administrative users to the DNS zones assigned to them. In the affected endpoints, the authorization check verified whether a requested zone was mapped to any user, rather than confirming that it was specifically mapped to the authenticated user.

As a result, an authenticated non-administrative user could access DNS zone information belonging to another user or tenant when that zone had been assigned to a different user. The same authorization weakness could also allow the user to reach DNS zone synchronization and import operations for zones outside their assigned scope.

The vulnerability has been fixed by enforcing user-specific zone mapping checks across the affected DNS APIs. Before returning or modifying DNS zone information, DDI Central now verifies that the requested zone is mapped to the authenticated user or that the user has administrative privileges.

Access controls have also been enforced for the applicable GET and modification endpoints. Requests involving zones that are not mapped to the requesting user are now rejected.

Impact:

Successful exploitation of this vulnerability could allow an authenticated non-administrative user to access DNS zone information belonging to other users, clusters, or tenants.

Depending on the affected operation, the user could also attempt unauthorized changes to DNS zone data. This could result in exposure of DNS configuration information, unauthorized DNS record modifications, traffic redirection, disruption of name resolution, or compromise of tenant isolation in multi-tenant deployments.

Steps to upgrade:

Update your DDI Central installation to the latest build 6301 using the applicable service pack.

After completing the upgrade, verify that the DDI Central Console is running the recommended build.

Acknowledgements:

This issue was reported by Tuan Anh 91.