Executive brief
Zoho ManageEngine Endpoint Central is a widely-deployed endpoint management platform used by organizations to manage and secure computers and mobile devices across their networks. A local privilege escalation vulnerability in the Agent component could allow a low-privilege user to gain administrative access during software upgrades, potentially compromising endpoint security and enabling unauthorized system changes or malware installation.
Technical details
A privilege escalation vulnerability exists in the Agent binaries within Endpoint Central that allows a low-privilege local user to elevate privileges during the agent upgrade process. The vulnerability is triggered during agent upgrade operations and can be exploited by an attacker with local access to escalate from a low-privilege context to a privileged account. This is a local attack vector requiring pre-existing access to an affected system. The vulnerability has been fixed in build 11.5.2605.01, released in March 2026.
Affected products
- Zoho ManageEngine Endpoint Central before 11.5.2605.01
Timeline
- 2026-09-07: disclosed
- 2026-03-05: patched: Fix released in build 11.5.2605.01