AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-12571

CRITICAL · CVSS 9.8 EPSS 1.63%

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

An authentication bypass vulnerability in ManageEngine DDI Central's password-reset workflow enables attackers to gain unauthorized access to user accounts, potentially leading to full account takeover. Organizations utilizing this software should prioritize immediate remediation efforts due to the critical severity of this issue, as it poses significant risks to user data and system integrity.

CVE
CVE-2026-12571
Severity
CRITICAL
CVSS
9.8
EPSS
1.63%

Original NVD Description

An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover.