×
×
×
×

CVE-2026-77698: Local privilege escalation due to Agent upgrade

This document highlights the security update for a vulnerability identified in the Agent binaries within Endpoint Central.

Release Notes

  • Severity: Medium
  • Update Release Date: March 2026
  • Reported by: Sandro Poppi via ManageEngine Bug Bounty Program

What Was the Problem?

A privilege escalation vulnerability in Endpoint Central was identified, which may allow a low privilege user to elevate into a privileged account during agent upgrade.

How to Fix It?

This vulnerability has been fixed and released in March 2026. The mitigation is available in build 11.5.2605.01.

Contact Support

If you have any questions or require further assistance, please contact our support team.