← Back to search

CVE-2026-12268

8.8 HIGH

Published 2026-09-28 · Updated 2026-09-29

AI risk analysis

Summary
This flaw allows PowerShell command injection in Windows DNS SPF/TXT record push, leading to remote code execution. Attackers can exploit this to gain full control over affected ManageEngine DDI Central instances.
Exploitability
Exploitation requires administrative access to the affected version of ManageEngine DDI Central and the ability to push DNS records. The vulnerability is relatively easy to exploit given these preconditions.
Blast radius
If exploited, the impact is high as it allows full remote code execution, potentially leading to complete compromise of the affected system and its network.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to ManageEngine DDI Central version 6201 or later.
rcednspowershellremote-code-execution

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

ManageEngine DDI Central versions below 6201 are vulnerable to PowerShell command injection in Windows DNS SPF/TXT record push leading to remote code execution.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-20

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.