Executive brief
ManageEngine Endpoint Central is an endpoint management platform used to manage and patch computer systems across organizations. Versions below 11.5.2600.15 contain a flaw in the agent tray's upload logs feature that allows users to delete files outside their authorized access scope, leading to privilege escalation. An attacker with local access could exploit this to gain elevated system privileges.
Technical details
The vulnerability is a privilege escalation flaw in the upload logs feature of the agent tray component, caused by an outdated dependency used in file handling operations. The vulnerability requires local access to the affected endpoint and allows an attacker to bypass file access controls and delete arbitrary files from directories the user normally cannot access. This abuse can lead to privilege escalation. The issue is fixed in versions 11.4.2528.35 and 11.5.2600.15 or later.
Affected products
- Zohocorp ManageEngine Endpoint Central below 11.5.2600.15 (including 11.4.2528.34 and below)
Timeline
- 2026-09-07: disclosed
- 2026-02-17: patched: Fixed in versions 11.4.2528.35 and 11.5.2600.15