Severity: Critical
CVE ID: CVE-2026-4734
Affected Software Version(s): DDI Central version 6.3.0/ Build 6300 and lower
Fixed Version: Build 6301
Fixed on: August 5, 2026
Details:
ManageEngine DDI Central build 6300 had an authentication and access-control vulnerability in the Windows DNS and DHCP agent synchronization APIs.
The affected API endpoints did not adequately authenticate requests from Windows Node Agents. The endpoints identified the requesting agent using the server_ip value supplied in the HTTP request body. Consequently, an unauthenticated remote attacker who supplied the IP address of an onboarded Windows DNS or DHCP server could impersonate that server and submit unauthorized synchronization requests.
Successful exploitation could allow an attacker to create, modify, or delete DHCP subnet information, DNS zones, DNS zone scopes, and DNS records associated with the impersonated Windows server.
The vulnerability has been fixed by enforcing authentication and authorization checks on the affected API endpoints. Requests are now validated before access to Windows DNS and DHCP synchronization operations is permitted. Requests without valid authentication or the required authorization are rejected before reaching the corresponding API handlers.
Impact:
Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to make unauthorized changes to DNS and DHCP data managed through DDI Central.
This could result in the deletion or modification of DHCP subnet scopes, unauthorized changes to DNS zones or records, DNS traffic redirection, incorrect network configuration, or disruption of DNS and DHCP management operations.
Steps to upgrade:
Update your DDI Central installation to the latest build 6301 using the applicable service pack.
After completing the upgrade, verify that the DDI Central Console and all applicable Windows Node Agent instances are running the recommended versions.
Acknowledgements:
This issue was reported by qquynh.