Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-12571: ManageEngine DDI Central Password Reset Bypass
CVE-2026-12571 · published 23 days ago
Summary
A security issue in ManageEngine DDI Central allows attackers to bypass the password reset process, potentially taking control of user accounts. This could lead to unauthorized access to sensitive data. Update ManageEngine DDI Central to the latest version to fix this issue.
What to do
- Update zohocorp manageengine_ddi_central to version 6201 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| zohocorp | manageengine_ddi_central | < 6201 |
Original advisory text
An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover.
An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover.
Severity
9.8
Critical
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS 2%
Type
CWE-287Improper Authentication
CWE-640Weak Password Recovery Mechanism for Forgotten Password
Timeline
Published11 Aug 2026
Updated30 Aug 2026
First seen11 Aug 2026
Monitor software like this
Free during beta