Authentication Bypass in ManageEngine DDI Central Password Reset Workflow
CVE-2026-12571

9.8CRITICAL

Key Information:

Vendor

Zohocorp

Vendor
CVE Published:
11 August 2026

What is CVE-2026-12571?

An authentication bypass vulnerability in the password-reset workflow of ManageEngine DDI Central enables unauthorized users to reset passwords without proper verification, leading to potential account takeover. This exploit poses significant risks to user accounts and sensitive data within the DDI Central environment.

Affected Version(s)

manageengine_ddi_central 0 < 6201

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.