Description
Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Arbitrary file write via HA Failover Config sync upload leading to remote code execution.
Published: 2026-09-28
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

This vulnerability allows an authenticated user to write an arbitrary file via the HA Failover Configuration sync upload mechanism of Zohocorp ManageEngine DDI Central. By uploading a malicious configuration file, an attacker can overwrite critical files on the server, leading to remote code execution on the affected system.

Affected Systems

Zohocorp ManageEngine DDI Central versions prior to 6201 are impacted. The affected components are the HA failover configuration sync and file upload handling logic within the DDI Central application.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity, and although an EPSS score is not available, the vulnerability remains significant. The lack of listing in the CISA KEV catalog does not mitigate the risk. The attack requires valid administrative credentials to access the HA failover configuration sync feature, after which file write privileges lead to code execution. Given the high severity and authenticated nature, remediation is strongly urged.

Generated by OpenCVE AI on September 28, 2026 at 17:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Zohocorp ManageEngine DDI Central to version 6201 or later to apply the vendor fix.
  • If an upgrade is not immediately possible, restrict access to the HA failover configuration sync feature to trusted administrators only, preventing unauthorized file uploads.
  • If feasible, disable the HA failover configuration sync functionality entirely to eliminate the attack surface.

Generated by OpenCVE AI on September 28, 2026 at 17:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22
CWE-94

Mon, 28 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-434

Mon, 28 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22
CWE-94

Mon, 28 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 28 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
Description Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Arbitrary file write via HA Failover Config sync upload leading to remote code execution.
Title Authenticated File Write via HA Failover Config Upload leads to RCE
First Time appeared Zohocorp
Zohocorp ddi Central
CPEs cpe:2.3:a:zohocorp:ddi_central:*:*:*:*:*:*:*:*
Vendors & Products Zohocorp
Zohocorp ddi Central
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Zohocorp Ddi Central
cve-icon MITRE

Status: PUBLISHED

Assigner: Zohocorp

Published:

Updated: 2026-09-28T15:07:59.748Z

Reserved: 2026-06-15T10:37:59.135Z

Link: CVE-2026-12264

cve-icon Vulnrichment

Updated: 2026-09-28T12:36:37.055Z

cve-icon NVD

Status : Received

Published: 2026-09-28T12:17:36.597

Modified: 2026-09-28T16:17:13.337

Link: CVE-2026-12264

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T18:00:04Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type