External risk intelligence

ManageEngine DDI Central Authentication Bypass Leads to Account Takeover

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-12571

ManageEngine DDI Central is a network management solution typically deployed as a centralized, externally reachable service to manage infrastructure. Because it serves as a critical management portal for DNS, DHCP, and IP address administration, it is commonly deployed in network-accessible environments, making its authentication interfaces a likely target for remote, internet-based interaction.

Authentication Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

An authentication bypass in ManageEngine DDI Central's password-reset function enables unauthorized account takeover. This vulnerability affects a product used for managing critical network services like DNS, DHCP, and IP addresses, and its external exposure makes it a potential target.

  • Bypass password reset to take over accounts.
  • Affects core network management, exposing systems.
  • Confirm if this critical network tool is deployed.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by targeting the password-reset process in ManageEngine DDI Central. This could be initiated remotely over the network, requiring no prior authentication or special user interaction. Successful exploitation could allow an attacker to gain unauthorized control of an existing account.

  • No authentication needed for access.
  • Target the password-reset workflow.
  • Risk of full account takeover.

Live Threat

Current exploitation, exposure, and threat context

An authentication bypass in ManageEngine DDI Central's password-reset workflow could allow an attacker to take over accounts. This is possible when supported by the advisory, where the attack vector is network-based, the attacker has no privileges, and there is no user interaction required.

  • Account takeover is at risk.
  • Unauthorized access to services.
  • Compromised system integrity.

Operational Fix

Recommended remediation, mitigation, and detection steps

ManageEngine DDI Central, a network management solution, presents a critical risk due to an authentication bypass flaw in its password-reset workflow. This vulnerability could allow unauthorized account takeover, necessitating immediate attention from infrastructure and security teams. The first practical step involves identifying all deployed instances of ManageEngine DDI Central, determining their network exposure and business criticality, and locating the accountable system owner to plan a risk-based remediation strategy.

  • Infrastructure and Security teams own resolution.
  • Verify DDI Central instance exposure and criticality.
  • Plan for vendor-coordinated remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is ManageEngine DDI Central?

ManageEngine DDI Central is an integrated software platform designed to manage critical network infrastructure services, specifically DNS, DHCP, and IP address management (IPAM). Organizations use it to centralize the oversight, configuration, and maintenance of their network's core connectivity components.

What does CVE-2026-12571 mean for account security?

This vulnerability is classified under CWE-287 (Improper Authentication) and CWE-640 (Weak Password Recovery Validation). In simple terms, it means the software's password-reset process is flawed, allowing an unauthorized person to bypass security checks and take control of any existing account without knowing the current credentials.

How can an attacker trigger this vulnerability?

An attacker can exploit this by sending requests directly to the password-reset workflow over the network. Crucially, this does not require the attacker to have an existing account, nor does it require any interaction from legitimate users to succeed; the system incorrectly trusts the request during the reset process.

Why is this CVE considered high risk for my network?

According to Halo Surface Signal, this software is often deployed as a centralized service accessible over the network to manage core infrastructure. Because it is frequently exposed to allow remote administration of DNS and DHCP, these authentication interfaces are prime targets for remote, internet-based unauthorized access.

Do I need to take immediate action if I run this software?

Yes. Your first step is to locate all instances of DDI Central within your environment. Once identified, confirm whether they are reachable over the network and determine who is responsible for the system. This allows you to prioritize these assets for vendor-provided updates once they are made available.

References