{"id":"CVE-2026-12265","published":"2026-09-28T13:17:21.550","lastModified":"2026-09-29T21:39:02.570","description":"Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Insufficient access control in HA failover endpoint leading to destructive PostgreSQL database operations.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-284"],"vendors":[],"products":[],"references":[{"url":"https://www.manageengine.com/dns-dhcp-ipam/security-updates/security-updates.html","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"This vulnerability allows unauthorized access to perform destructive operations on the PostgreSQL database during HA failover, leading to potential data loss or corruption.","exploitability":"Exploitation requires access to the HA failover endpoint and knowledge of the system configuration. Precondition is the presence of an attacker with low-level privileges.","blast_radius":"If exploited, the impact could be severe, including data loss or corruption affecting multiple systems relying on the DDI Central service.","remediation":"Upgrade to version 6201 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["database","ha-failover","postgres","data-loss"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-30T09:07:19.005Z"}}