OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-12269

HIGH · CVSS 8.8 EPSS 6.99%

Source: NVD + CISA KEV + EPSS · Published 2026-09-28 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

A vulnerability exists in the Keepalived configuration of Zohocorp ManageEngine DDI Central versions 6.2.0 and below 6201, allowing authenticated operator-level users to inject malicious configurations. This could lead to unauthorized command execution with root privileges on the host system, posing a significant security risk. Organizations using affected versions should prioritize remediation to mitigate potential exploitation.

CVE
CVE-2026-12269
Severity
HIGH
CVSS
8.8
EPSS
6.99%

Original NVD Description

Zohocorp ManageEngine DDI Central 6.2.0 build below 6201 had a Keepalived configuration injection vulnerability in the HA configuration workflow. This issue could allow an authenticated operator-level user to modify the Keepalived configuration and potentially execute commands as root on the DDI Central host.