CVE-2026-85640: Privilege Escalation
Published Sep 7, 2026
·Updated
Zohocorp ManageEngine Endpoint Central versions below 11.5.2600.15 are vulnerable to Privilege Escalation Due to Outdated Component
Affected Software
1 affected component
Zohocorp ManageEngine Endpoint Central<11.5.2600.15
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ManageEngine Endpoint Centralto a version that resolves this vulnerability.Fixed in 11.5.2600.15
Event History
Sep 7, 2026
CVE Published
via MITRE·10:45 AM
Data Sourced
via MITRE·10:45 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who is realistically exposed to this issue?
Endpoint Central deployments running a version below 11.5.2600.15 are affected. Exploitation requires an attacker to have local access and low-level privileges on the affected system.
2
Does exploitation require user interaction or remote access?
No user interaction is required. The published vector identifies the attack as local, so it does not describe exploitation over the network.
3
How can I determine whether my deployment is affected?
Check the installed ManageEngine Endpoint Central version. Versions below 11.5.2600.15 are identified as vulnerable.