Sceawere

Vulnerability Detail

CVE-2026-77698UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

ManageEngine Endpoint Central LPE

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.7
Creation Date
2h ago
Vendor
Zohocorp
Product
ManageEngine Endpoint Central
Attack Type
CWE-269: Improper Privilege Management
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Zohocorp ManageEngine Endpoint Central versions before 11.5.2605.01 are vulnerable to local privilege escalation due to Agent upgrade.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.7",
  "pubDate": "2026-09-07T10:16:53.673Z",
  "pubdate": "2026-09-07T10:16:53.673Z",
  "executiveSummary": "ManageEngine Endpoint Central versions prior to 11.5.2605.01 contain a local privilege escalation (LPE) vulnerability triggered during the agent upgrade process.\nThis vulnerability allows a locally authenticated, low-privileged attacker to execute arbitrary code with elevated system privileges.\nThe flaw resides in the handling of the agent upgrade mechanism, where insufficient validation or insecure file operations permit an attacker to manipulate the update sequence.\nBy successfully exploiting this vulnerability, an adversary can achieve full system compromise, gaining administrative control over the underlying host.\nThis risk is particularly significant in enterprise environments where Endpoint Central manages large fleets of workstations and servers, as the exploitation provides a direct path for horizontal and vertical privilege movement within the infrastructure.\nSuccessful exploitation requires local access to the affected system, but does not necessitate prior elevated privileges.",
  "technicalDetails": "The vulnerability is rooted in a flawed implementation of the automated agent upgrade workflow within ManageEngine Endpoint Central, specifically in versions before 11.5.2605.01.\nThe root cause pertains to an insecure mechanism used by the agent update routine when performing file operations, such as moving, replacing, or executing binaries during the upgrade phase.\nAttack flow typically begins with an unprivileged attacker gaining a local presence on the endpoint where the ManageEngine agent is installed.\nThe attacker monitors the agent's background activities to identify the timing or the filesystem structures utilized by the update process. Given the agent operates with SYSTEM-level privileges, any vulnerability in how it handles external files or command-line arguments during the update allows for arbitrary code execution in the context of the SYSTEM user.\nExploitation involves the attacker placing malicious payloads, symbolic links, or manipulating configuration files that the agent process consumes while running with high integrity. By coercing the service to interact with these malicious inputs during the upgrade, the agent effectively executes the attacker's payload as SYSTEM.\nThe vulnerable component is the agent's internal upgrade management utility, which fails to strictly enforce integrity checks or restrict access to the directories used for staging update binaries. Because the update service maintains high persistence and privilege, it becomes an ideal target for local privilege escalation.\nThe post-exploitation impact includes the total takeover of the affected host. Once code is executed at the SYSTEM level, the attacker can install backdoors, dump memory for credentials, disable security software, or exfiltrate sensitive data stored on the endpoint.\nThis vulnerability does not require authentication to the agent management console itself, nor does it require network exposure, as the attack vector is localized to the filesystem and process interaction on the compromised host. The dependency is strictly on the vulnerable version of the agent software."
}
CVE-2026-77698: ManageEngine Endpoint Central LPE (MEDIUM Severity, CVSS: 5.7) - Sceawere