Privilege Escalation Vulnerability in Zoho ManageEngine Endpoint Central
CVE-2026-77697

6.3MEDIUM

Key Information:

Vendor

Zohocorp

Vendor
CVE Published:
7 September 2026

What is CVE-2026-77697?

Zoho ManageEngine Endpoint Central versions prior to 11.4.2540.23 are susceptible to a privilege escalation vulnerability that occurs during JAR extraction. This security flaw allows an attacker to exploit system privileges, potentially leading to unauthorized access and control over affected systems. Organizations utilizing these versions are advised to apply the necessary updates to mitigate the risks associated with this vulnerability.

Affected Version(s)

ManageEngine Endpoint Central 0 < 11.4.2540.23

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.