Junglewise Threat Intelligence

CVE-2026-77699: Zoho ManageEngine Endpoint Central privilege escalation via DLL loading

CVE-2026-77699 · Severity: medium · CVSS 5 · Published 2026-09-07

Vendors: Zoho.

Executive brief

Zoho ManageEngine Endpoint Central is an IT operations management platform used by organizations to manage endpoints and systems across networks. A local privilege escalation vulnerability in the Agent binaries allows low-privilege users to elevate their access to administrator-level privileges by exploiting unsafe DLL loading from untrusted paths. This could allow compromised or malicious user accounts to gain control of critical IT infrastructure management functions.

Technical details

This is a DLL preloading / DLL hijacking vulnerability in the Endpoint Central Agent binaries, caused by loading dynamic libraries from untrusted or uncontrolled search paths. A low-privilege user on the same system can exploit this by placing a malicious DLL in an accessible location, which is then loaded during Agent execution with elevated privileges. The attack is local only and does not require network access or authentication to the Endpoint Central server. An attacker can achieve privilege escalation to SYSTEM or administrative account level. The vulnerability is fixed in build 11.5.2605.01, released in March 2026.

Affected products

  • Zoho ManageEngine Endpoint Central below 11.5.2605.01

Timeline

  • 2026-09-07: disclosed
  • 2026-03-05: patched: Fixed in build 11.5.2605.01

References

Related threats