# Privilege Escalation Vulnerability During JAR Extraction Last Updated On: 30 Jul 2026 2 minutes read This document addresses the privilege escalation vulnerability in the Endpoint Central agent during JAR file extraction. ## Security Advisory **Severity:** Medium **Attack Vector:** Local **Fixed build:** For versions 11.5.2600.18 or below, upgrade to version 11.5.2600.19. For versions 11.4.2540.22 or below, upgrade to version 11.4.2540.23. **Fix release date:** 2026-02-16 **Reported by:** Sandro Poppi via the ZohoCorp Bug Bounty Program ## What was the problem? During a patch scan, the Endpoint Central agent extracted JAR files in a directory controlled by a standard user. This could be exploited by a local user to elevate privileges to SYSTEM. We have addressed the issue to prevent unauthorized privilege escalation. ## How to fix it? Upgrading to the latest version is strongly advised due to the severity of this vulnerability. To upgrade, follow the steps below: 1. Log in to the Endpoint Central console and click your current build number in the top-right corner. 2. You will be able to find the latest build applicable to your installation. 3. **Download the PPM** and complete the upgrade. For any further questions or concerns regarding this issue, write a mail to our [support team](mailto:endpointcentral-support@manageengine.com).