Description
Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Insufficient access control in HA failover endpoint leading to destructive PostgreSQL database operations.
Published: 2026-09-28
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: Data Destruction
Action: Immediate Patch
AI Analysis

Impact

Zohocorp ManageEngine DDI Central versions before 6201 contain an insufficient access control flaw on the HA failover endpoint. The endpoint allows destructive PostgreSQL database operations that can delete or corrupt entire configuration data when accessed. The flaw can be abused to achieve full data loss or compromise of system integrity.

Affected Systems

The affected product is Zohocorp DDI Central, any installation with a version earlier than 6201. These releases expose the failover endpoint without proper authorization checks, allowing attackers to trigger destructive database actions.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity, and while the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the attack surface is likely reachable over the network. Based on the description, it is inferred that the HA failover endpoint can be accessed remotely, making the flaw exploitable by an attacker who can communicate with that endpoint. The absence of known widespread exploits does not reduce the severity of the potential impact and requires urgent action.

Generated by OpenCVE AI on September 28, 2026 at 15:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to DDI Central version 6201 or later
  • Disable the HA failover feature if it is not required
  • Restrict network access to the HA failover endpoint, for example by using firewall rules to allow only trusted IP addresses
  • Apply the principle of least privilege to any services that can access the HA failover endpoint

Generated by OpenCVE AI on September 28, 2026 at 15:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 28 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Description Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Insufficient access control in HA failover endpoint leading to destructive PostgreSQL database operations.
Title Missing Authorization on HA Failover Config allows Complete Data Destruction
First Time appeared Zohocorp
Zohocorp ddi Central
CPEs cpe:2.3:a:zohocorp:ddi_central:*:*:*:*:*:*:*:*
Vendors & Products Zohocorp
Zohocorp ddi Central
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Zohocorp Ddi Central
cve-icon MITRE

Status: PUBLISHED

Assigner: Zohocorp

Published:

Updated: 2026-09-28T13:22:47.541Z

Reserved: 2026-06-15T10:38:15.455Z

Link: CVE-2026-12265

cve-icon Vulnrichment

Updated: 2026-09-28T13:22:43.460Z

cve-icon NVD

Status : Received

Published: 2026-09-28T13:17:21.550

Modified: 2026-09-28T14:17:14.640

Link: CVE-2026-12265

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T17:45:04Z

Weaknesses