Arbitrary File Write Vulnerability in Zohocorp ManageEngine DDI Central
CVE-2026-12264

8.8HIGH

Key Information:

Vendor

Zohocorp

Vendor
CVE Published:
28 September 2026

What is CVE-2026-12264?

A critical vulnerability allows attackers to perform arbitrary file write operations through the HA Failover Config sync upload feature in Zohocorp's ManageEngine DDI Central. This flaw can lead to remote code execution, enabling unauthorized users to gain control over affected systems. Organizations using versions prior to 6201 are strongly advised to update their products to mitigate this security risk. Ensure the integrity of your network by implementing the latest security patches available from the vendor.

Affected Version(s)

DDI Central 0 < 6201

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.