Local Privilege Escalation Vulnerability in ManageEngine Endpoint Central by Zoho
CVE-2026-77699

5MEDIUM

Key Information:

Vendor

Zohocorp

Vendor
CVE Published:
7 September 2026

What is CVE-2026-77699?

A vulnerability in ManageEngine Endpoint Central allows for local privilege escalation due to inadequate validation in DLL loading from untrusted paths. This issue impacts versions prior to 11.5.2605.01, potentially enabling attackers to execute arbitrary code with elevated privileges, posing serious security risks to affected systems.

Affected Version(s)

ManageEngine Endpoint Central 0 < 11.5.2605.01

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.