# CVE-2026-75868 ## Improper authorization in Windows DHCP option handling allowing cross-cluster DNS Server option changes fixed in build 6301 **Severity:** High **CVE ID:** CVE-2026-75868 **Affected Software Version(s):** DDI Central 6.3.0 / Build 6300 **Fixed Version:** Build 6301 **Fixed on:** August 18, 2026 **Details:** ManageEngine DDI Central 6.3.0 build 6300 had an authorization vulnerability in the Windows DHCP option configuration workflow. The affected functionality did not adequately verify whether an authenticated operator had permission to manage the cluster and subnet associated with the specified Windows DHCP configuration before allowing DHCP option changes. This issue could allow an authenticated non-administrator operator with access to one DDI Central cluster to modify DHCP options on a Windows subnet belonging to another cluster that the operator was not authorized to access. The demonstrated case involved modifying DHCP option 6 (DNS Servers) for an inaccessible subnet. The vulnerability has been fixed by adding scoped-operator authorization checks and cluster permission checks to ensure that DHCP options can be modified only for subnets and clusters for which the user has the required permissions. **Impact:** Successful exploitation of this vulnerability could allow an authenticated operator to replace the DNS Server DHCP option of a Windows subnet in an inaccessible cluster. As a result, clients obtaining or renewing DHCP leases on the affected subnet could be directed to an unauthorized DNS resolver, potentially affecting name resolution, redirecting traffic, or causing DNS resolution failures. **Steps to upgrade:** Update your DDI Central Console and Node Agent instances to the fixed build or later using the corresponding service pack. **Acknowledgements:** This issue was reported by sealldev.