CVE-2026-12571 PUBLISHED

Authentication Bypass Leading to Account Takeover

Assigner: Zohocorp
Reserved: 18.06.2026 Published: 11.08.2026 Updated: 12.08.2026

An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8

Product Status

Vendor zohocorp
Product manageengine_ddi_central
Versions Default: unaffected
  • affected from 0 to 6201 (excl.)

References

Problem Types

  • CWE-287 Improper Authentication CWE
  • CWE-640 Weak Password Recovery Mechanism for Forgotten Password CWE

Impacts

  • CAPEC-115 Authentication Bypass