CVE-2026-12571
9.8Zoho Corporation · ManageEngine DDI Central
An authentication bypass vulnerability in the ManageEngine DDI Central password reset workflow allows remote attackers to perform full account takeover.
Executive summary
A critical authentication bypass in ManageEngine DDI Central allows unauthenticated attackers to gain unauthorized access and compromise administrative accounts.
Vulnerability
This vulnerability involves an improper authentication mechanism within the password recovery process. It allows an unauthenticated attacker to manipulate the workflow and take over legitimate user accounts.
Business impact
Successful exploitation of this flaw grants an attacker full control over the affected ManageEngine DDI Central instance. Given the CVSS score of 9.8, this represents a critical risk: it could lead to total system compromise, unauthorized data exfiltration, and the manipulation of network infrastructure configurations.
Remediation
Immediate Action: Upgrade to version 6201 or later immediately to resolve the authentication vulnerability.
Proactive Monitoring: Review system logs for suspicious password reset requests or multiple unauthorized access attempts originating from unusual sources.
Compensating Controls: Ensure that the management interface is not exposed to the public internet and restrict access to authorized network segments only.
Exploitation status
Public Exploit Available: No (unknown).
Analyst recommendation
This vulnerability presents a severe risk to organizational infrastructure due to the potential for complete system takeover. Administrators must prioritize updating ManageEngine DDI Central to version 6201 or higher as the primary and most effective mitigation strategy.