CVE-2026-77698: Privilege Escalation
Zohocorp ManageEngine Endpoint Central versions before 11.5.2605.01 are vulnerable to local privilege escalation due to Agent upgrade.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ManageEngine Endpoint Centralto a version that resolves this vulnerability.Fixed in 11.5.2605.01
Event History
Frequently Asked Questions
Who can exploit this issue?
Exploitation requires local access, low privileges, and user interaction. It is therefore most relevant on systems where a low-privileged user can access the Endpoint Central agent upgrade process.
Which deployments are affected?
ManageEngine Endpoint Central versions before 11.5.2605.01 are affected. The issue is specifically associated with agent upgrade functionality.
What is the remediation?
Upgrade ManageEngine Endpoint Central to version 11.5.2605.01 or later. The provided information does not identify an alternative mitigation if upgrading cannot be performed immediately.