← back
CVE-2026-12264high

Authenticated File Write via HA Failover Config Upload leads to RCE

18Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.8
exploitation probability
—
observed exploitation
nono source reports it
Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Arbitrary file write via HA Failover Config sync upload leading to remote code execution.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
Zohocorp · DDI Central