# CVE-2026-19421 ## PowerShell injection in Windows DNS TXT record handling leading to remote code execution fixed in build 6301 **Severity:** High **CVE ID:** CVE-2026-19421 **Affected Software Version(s):** DDI Central 6.3.0 / Build 6300 **Fixed Version:** Build 6301 **Fixed on:** August 18, 2026 **Details:** ManageEngine DDI Central had a PowerShell injection vulnerability in the handling of TXT record values for managed Windows DNS servers. User-supplied TXT record values were incorporated into PowerShell commands used by DDI Central to perform DNS record operations on the managed Windows server without sufficient validation. An authenticated user with permission to manage a Windows-backed DNS zone could potentially supply a specially crafted TXT record value that, during DNS record processing, could result in arbitrary command execution on the managed Windows DNS server using the account configured by DDI Central to manage that server. The vulnerability has been addressed by introducing additional validation for TXT record values to prevent unsafe input from being executed through Windows server management operations. **Impact:** Successful exploitation of this vulnerability could allow an authenticated user with the required DNS zone privileges to execute arbitrary commands on a managed Windows DNS server with the privileges of the Windows account configured for DDI Central DNS management. **Steps to upgrade:** Update your DDI Central Console and applicable Windows DDI management components to 6301 or later using the corresponding service pack. **Acknowledgements:** This issue was reported by qquynh.