CVE-2026-12265: high-severity vulnerability in Zohocorp DDI Central
Missing Authorization on HA Failover Config allows Complete Data Destruction
Published
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.8epss 0.9%
exploitation probability
0.9%top 42% of all CVEs
observed exploitation
nono source reports it
Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Insufficient access control in HA failover endpoint leading to destructive PostgreSQL database operations.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
Zohocorp · DDI CentralRelated CVEs — Zohocorp DDI Central
In the same product, most dangerous first.
CVE-2026-12269HIGHAuthenticated File Write to RCE via keepalived in DDI CentralEPSS 7.0%CVE-2026-12268HIGHAuthenticated PowerShell Injection leads to RCEEPSS 4.7%CVE-2026-12267HIGHAuthenticated PowerShell Injection in DNS Query Resolution Policy leads to RCEEPSS 3.6%CVE-2026-12264HIGHAuthenticated File Write via HA Failover Config Upload leads to RCEEPSS 2.0%