CVE-2026-77697: Privilege Escalation
Published Sep 7, 2026
·Updated
Zohocorp ManageEngine Endpoint Central versions below 11.4.2540.23 are vulnerable to Privilege Escalation During JAR Extraction
Affected Software
1 affected component
Zohocorp ManageEngine Endpoint Central<11.4.2540.23
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Zohocorp ManageEngine Endpoint Centralto a version that resolves this vulnerability.Fixed in 11.4.2540.23
Event History
Sep 7, 2026
CVE Published
via MITRE·10:49 AM
Data Sourced
via MITRE·10:49 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which Endpoint Central installations are affected?
ManageEngine Endpoint Central versions below 11.4.2540.23 are affected. Versions at or above 11.4.2540.23 are not identified as vulnerable by the provided information.
2
What level of access does an attacker need to exploit this issue?
The CVSS vector indicates local access and low privileges are required. No user interaction is required.
3
What is the potential impact of successful exploitation?
Successful exploitation can result in privilege escalation during JAR extraction. The CVSS vector indicates low impact to confidentiality, integrity, and availability, with scope changed.