Arbitrary File Write Vulnerability in Zohocorp ManageEngine DDI Central
CVE-2026-12264
8.8HIGH
What is CVE-2026-12264?
A critical vulnerability allows attackers to perform arbitrary file write operations through the HA Failover Config sync upload feature in Zohocorp's ManageEngine DDI Central. This flaw can lead to remote code execution, enabling unauthorized users to gain control over affected systems. Organizations using versions prior to 6201 are strongly advised to update their products to mitigate this security risk. Ensure the integrity of your network by implementing the latest security patches available from the vendor.
Affected Version(s)
DDI Central 0 < 6201