Keepalived Configuration Injection Vulnerability in ManageEngine DDI Central by ZohoCorp
CVE-2026-12269

8.8HIGH

Key Information:

Vendor

Zohocorp

Vendor
CVE Published:
28 September 2026

What is CVE-2026-12269?

A configuration injection vulnerability exists in the Keepalived setup of ZohoCorp's ManageEngine DDI Central versions 6.2.0 and below 6201. This flaw allows authenticated operator-level users to alter the Keepalived configuration, which may lead to unauthorized command execution with root privileges on the DDI Central host, posing significant security risks to the system.

Affected Version(s)

DDI Central 0 < 6201

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.