Security Updates - CVE Database

CVE-2026-75869

PowerShell injection in Windows DHCP DNS settings allowing cross-cluster command execution fixed in build 6301

Severity: High

CVE ID: CVE-2026-75869

Affected Software Version(s): DDI Central 6.3.0 / Build 6300 and below

Fixed Version: Build 6301

Fixed on: August 18, 2026

Details:

ManageEngine DDI Central 6.3.0 build 6300 had an authorization and command injection vulnerability in the Windows DHCP DNS settings configuration workflow. The affected functionality did not adequately verify that the Windows DHCP subnet being modified belonged to a cluster that the authenticated operator was authorized to manage.

Additionally, user-supplied DNS suffix values were incorporated into PowerShell commands used to configure DNS settings on managed Windows DHCP servers without sufficient validation. An authenticated non-administrator operator could therefore submit specially crafted DNS settings for a subnet in another inaccessible cluster, potentially causing attacker-controlled PowerShell commands to be sent to the managed Windows DHCP server.

The vulnerability has been fixed by adding cross-cluster authorization checks and script injection prevention controls to ensure that users can modify only authorized Windows DHCP resources and that unsafe input cannot be incorporated into PowerShell commands.

Impact:

Successful exploitation of this vulnerability could allow an authenticated scoped operator to bypass DDI Central's cluster-level administrative isolation and cause attacker-controlled PowerShell commands to be dispatched to a Windows DHCP server outside the operator's authorized cluster.

Commands would execute within the context of the Windows management service account used by DDI Central, potentially allowing access to or modification of host data, DHCP configuration, services, and other resources available to that account.

Steps to upgrade:

Update your DDI Central Console and Node Agent instances to the fixed build or later using the corresponding service pack.

Acknowledgements:

This issue was reported by sealldev.