Security Updates - CVE Database

CVE-2026-95643

Unauthenticated GSS-TSIG keytab update in Linux Node Agent fixed in build 6500

Severity: High

CVE ID: CVE-2026-95643

Affected Software Version(s): DDI Central 6.3.1 / Build 6301 and below

Fixed Version: Build 6500

Fixed on: September 17, 2026

Details:

ManageEngine DDI Central 6.3.1 build 6301 and earlier contained a command injection vulnerability in the telnet connectivity feature.

The issue affected the handling of IPv6 address inputs in the /ipam/telnet/ functionality. Certain IPv6 values containing a scope identifier could pass the existing IP address validation and subsequently be incorporated into PowerShell commands executed on the managed Windows node.

The underlying issue occurred because IPv6 scope identifiers were accepted without sufficient character validation. A specially crafted value could therefore escape the expected PowerShell string context and cause unintended PowerShell commands to be executed.

The vulnerability has been fixed by enhancing input validation in the DDI telnet connectivity feature. IPv6 scope identifiers are now appropriately validated and rejected when unsafe, command inputs are restricted using additional allow listing controls, and port values are explicitly converted to integers before processing. These protections are applied at the command execution layer so that all callers using the affected functionality are protected.

Impact:

Successful exploitation of this vulnerability could allow a user with access to the affected telnet connectivity functionality to supply a specially crafted IPv6 address and inject PowerShell commands into operations executed on a managed Windows node.

Depending on the privileges of the Windows service account used for the operation, injected commands could potentially access or modify system data, network configuration, services, or other resources available to that account. The issue was classified as Remote Code Execution (RCE).

Steps to upgrade:

Update your DDI Central Console and applicable Node Agent instances to build 6500 or later using the corresponding service pack.

Acknowledgements:

This issue was reported by Zewei Zhang from NSFOCUS TIANJI Lab.