Severity: High
CVE ID: CVE-2026-75867
Affected Software Version(s): DDI Central 6.3.0 / Build 6300
Fixed Version: Build 6301
Fixed on: August 18, 2026
Details:
ManageEngine DDI Central version 6.3.0 build 6300 had an authorization vulnerability in the Windows DHCP filter-list configuration workflow. The affected functionality did not adequately verify whether an authenticated operator had permission to manage the cluster associated with the specified Windows DHCP server before allowing changes to its allow/deny filter-list state.
This issue could allow an authenticated non-administrator operator with access to one DDI Central cluster to modify the DHCP filter-list configuration of a Windows DHCP server belonging to another cluster that the operator was not authorized to access.
The vulnerability has been fixed by adding authorization and cluster permission checks to ensure that scoped users can modify Windows DHCP filter-list configurations only for servers and clusters for which they have the required permissions.
Impact:
Successful exploitation of this vulnerability could allow an authenticated operator to enable or disable the Windows DHCP allow and deny lists of a server in an inaccessible cluster. This could alter server-wide DHCP admission controls and potentially allow clients that should have been restricted to obtain DHCP service.
Steps to upgrade:
Update your DDI Central Console and Node Agent instances to the fixed build or later using the corresponding service pack.
Acknowledgements:
This issue was reported by sealldev.