Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-12571: ManageEngine DDI Central Password Reset Bypass

CVE-2026-12571 · published 23 days ago
Summary

A security issue in ManageEngine DDI Central allows attackers to bypass the password reset process, potentially taking control of user accounts. This could lead to unauthorized access to sensitive data. Update ManageEngine DDI Central to the latest version to fix this issue.

What to do
  • Update zohocorp manageengine_ddi_central to version 6201 or later.
Affected software
VendorProductAffected versions
zohocorp manageengine_ddi_central < 6201
Original advisory text
An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover.
An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover.
Severity
9.8 Critical
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS 2%
Type
CWE-287Improper Authentication
CWE-640Weak Password Recovery Mechanism for Forgotten Password
Timeline
Published11 Aug 2026
Updated30 Aug 2026
First seen11 Aug 2026
Sources
CVE-2026-12571 · MITRE
Monitor software like this
Free during beta