Local Privilege Escalation in ManageEngine Endpoint Central by Zohocorp
CVE-2026-77698

5.7MEDIUM

Key Information:

Vendor

Zohocorp

Vendor
CVE Published:
7 September 2026

What is CVE-2026-77698?

ManageEngine Endpoint Central, developed by Zohocorp, is susceptible to a local privilege escalation vulnerability. This issue arises during the Agent upgrade process in versions prior to 11.5.2605.01, potentially allowing unauthorized users to escalate their privileges on the system. It is imperative for organizations using this software to apply the latest updates and patches to mitigate any security risks associated with this vulnerability.

Affected Version(s)

ManageEngine Endpoint Central 0 < 11.5.2605.01

References

CVSS V3.1

Score:
5.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.