Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 28 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 28 Sep 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Zohocorp ManageEngine DDI Central 6.2.0 build below 6201 had a Keepalived configuration injection vulnerability in the HA configuration workflow. This issue could allow an authenticated operator-level user to modify the Keepalived configuration and potentially execute commands as root on the DDI Central host. | |
| Title | Authenticated File Write to RCE via keepalived in DDI Central | |
| First Time appeared |
Zohocorp
Zohocorp ddi Central |
|
| Weaknesses | CWE-269 CWE-434 |
|
| CPEs | cpe:2.3:a:zohocorp:ddi_central:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Zohocorp
Zohocorp ddi Central |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Zohocorp
Published:
Updated: 2026-09-28T16:32:29.041Z
Reserved: 2026-06-15T10:39:06.686Z
Link: CVE-2026-12269
Updated: 2026-09-28T16:22:38.073Z
Status : Received
Published: 2026-09-28T11:16:44.177
Modified: 2026-09-28T17:17:49.010
Link: CVE-2026-12269
No data.
OpenCVE Enrichment
Updated: 2026-09-28T16:22:49Z