Description
An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover.
Published: 2026-08-11
Score: 9.8 Critical
EPSS: 1.6% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authentication bypass exists in the password‑reset workflow of ManageEngine DDI Central that allows an attacker to reset a user’s password without proper authentication, leading to full account takeover. This vulnerability is classified under CWE‑287 and CWE‑640.

Affected Systems

The flaw is present in ManageEngine DDI Central, a DNS, DHCP, and IP address management solution from Zohocorp. The CVE listing does not specify vulnerable versions or release numbers, so any installation of the product potentially is affected until an official patch is released.

Risk and Exploitability

The CVSS score of 9.8 indicates a critical severity, reflecting full compromise of user credentials. The EPSS score of 2% indicates a low but nonzero probability of exploitation. The vulnerability is not listed in CISA KEV. The description indicates that an attacker can trigger the bypass by manipulating the password‑reset workflow. No further environmental constraints are described.

Generated by OpenCVE AI on August 13, 2026 at 02:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest security update for ManageEngine DDI Central released by Zohocorp.
  • Temporarily disable the password‑reset feature or lock down the endpoint to trusted IP ranges until the patch is applied.
  • Enable multi‑factor authentication for all administrative accounts and monitor authentication logs for suspicious reset attempts.

Generated by OpenCVE AI on August 13, 2026 at 02:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
First Time appeared Zohocorp
Zohocorp manageengine Ddi Central
Vendors & Products Zohocorp
Zohocorp manageengine Ddi Central

Tue, 11 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover.
Title Authentication Bypass Leading to Account Takeover
Weaknesses CWE-287
CWE-640
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Zohocorp Manageengine Ddi Central
cve-icon MITRE

Status: PUBLISHED

Assigner: Zohocorp

Published:

Updated: 2026-08-12T04:00:34.213Z

Reserved: 2026-06-18T05:15:34.817Z

Link: CVE-2026-12571

cve-icon Vulnrichment

Updated: 2026-08-11T19:21:05.324Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T17:17:46.940

Modified: 2026-08-31T19:22:43.473

Link: CVE-2026-12571

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T04:45:02Z

Weaknesses
  • CWE-287

    Improper Authentication

  • CWE-640

    Weak Password Recovery Mechanism for Forgotten Password