LiveActive security incident?Get immediate response
CVE Record

CVE-2026-12571: Authentication Bypass Leading to Account Takeover

An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover.

CriticalCVSS 9.8Not KEV-listedUpdated
Glexia's TakeAutomated analysiscritical

Security readout for executives and security teams

Plain-English summary

A flaw in ManageEngine DDI Central’s password-reset process can let an unauthenticated attacker take over an account. Successful compromise could expose or alter sensitive DNS, DHCP, and IP address management data and disrupt service. The supplied evidence rates the issue critical, but does not identify exact affected releases or confirm exploitation.

Executive priority

Treat as an immediate investigation and remediation priority because account takeover of core network-management infrastructure could enable sensitive-data loss, configuration manipulation, or disruption. First establish product inventory and vendor-confirmed applicability; then remediate affected instances promptly. Escalate any suspicious password-reset or administrative activity to incident response.

Technical view

CVE-2026-12571 is an authentication bypass in DDI Central’s password-reset workflow, classified under CWE-287 and CWE-640. CVSS 3.1 is 9.8: network-accessible, low complexity, no privileges or user interaction, with high confidentiality, integrity, and availability impact. The bundle’s version entry is ambiguous and insufficient for release-level scoping.

Likely exposure

Potentially exposed organizations are those operating ManageEngine DDI Central with the vulnerable password-reset workflow. Network-reachable instances warrant particular attention. The supplied version value, “0,” and default-unaffected status do not establish which releases are vulnerable, so inventory must be reconciled with current vendor guidance.

Exploitation context

The supplied record is not listed in CISA KEV, and no cited source in the bundle confirms active exploitation or public exploit availability. Absence from KEV does not establish safety. Its unauthenticated, network-accessible characteristics indicate serious theoretical risk, but observed exploitation remains unverified from the provided evidence.

Researcher notes

The public bundle supports the vulnerability class, product, workflow, and CVSS rating. It does not provide reliable affected-version boundaries, patch identifiers, technical root-cause detail, or evidence of exploitation. The version value “0” may reflect incomplete record data and should not be interpreted as a real release without vendor confirmation.

Mitigation direction

  • Identify all ManageEngine DDI Central deployments and record their exact versions.
  • Review the vendor security-updates page for affected releases and approved remediation.
  • Apply the vendor-provided update or mitigation as soon as applicability is confirmed.
  • Restrict unnecessary network access to DDI Central, especially password-reset interfaces.
  • Monitor accounts and administrative changes for signs of unauthorized access.

Validation and detection

  • Confirm each deployed version against the vendor’s affected-version guidance.
  • Verify vendor remediation is installed on every applicable instance.
  • Test that password resets require the expected identity verification controls.
  • Review recent password resets, account changes, and administrative activity for anomalies.
  • Confirm external and internal network exposure matches organizational requirements.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · medium confidence lookup

CWE-287: Credential and account abuse lookup

Authentication and credential weaknesses can make valid-account abuse and credential telemetry useful review starting points. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cwe · low confidence lookup

CWE-640: Exact CWE lookup

Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
description · low confidence lookup

Credential and access behavior lookup

The CVE wording references authentication or credential exposure, so valid-account and credential-access review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2026-12571 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Critical
CVSS
9.8 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
3Timeline events
1ADP providers
2Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: yesTechnical Impact: total

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
9.8CVSS 3.1CriticalCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H3.95.9Zohocorp

Vulnerability scoring details

Base CVSS 3.1 score

9.8Critical
CVSS 3.1 vector shape for CVE-2026-12571Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
other:ssvc
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
zohocorpmanageengine_ddi_central0unaffected
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-287 · source CWE mapping

Improper Authentication

Improper Authentication represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.

CWE-640 · source CWE mapping

Weak Password Recovery Mechanism for Forgotten Password

Weak Password Recovery Mechanism for Forgotten Password represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.