Description
Zohocorp ManageEngine Endpoint Central versions below 11.4.2540.23 are vulnerable to Privilege Escalation During JAR Extraction
Published: 2026-09-07
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

This vulnerability involves the unvalidated extraction of JAR files in ManageEngine Endpoint Central, allowing a user to elevate privileges. The flaw corresponds to CWE‑269, representing unauthorized access to privileged resources, and can enable a user with limited permissions to perform operations that should be restricted.

Affected Systems

Zohocorp ManageEngine Endpoint Central is affected. Versions before 11.4.2540.23 are vulnerable; any instance running a lower release must be considered at risk.

Risk and Exploitability

The CVSS score of 6.3 indicates moderate severity, and the EPSS score is not released, suggesting no publicly available exploitation data. The vulnerability is not listed in the CISA KEV catalog. The likely attack path infers that local access to the JAR extraction mechanism is required; an attacker with user‑level privileges could take advantage of the flaw to write files to privileged locations during extraction, thereby escalating privileges.

Generated by OpenCVE AI on September 7, 2026 at 14:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade ManageEngine Endpoint Central to version 11.4.2540.23 or later to eliminate the vulnerability.
  • Restrict local permissions to prevent users from running the JAR extraction mechanism or modify the application configuration to disallow extraction of files to privileged directories.
  • Implement monitoring and alerts for anomalous file creation or privilege changes during JAR extraction, and enforce strict access controls on extracted files.

Generated by OpenCVE AI on September 7, 2026 at 14:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 07 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Description Zohocorp ManageEngine Endpoint Central versions below 11.4.2540.23 are vulnerable to Privilege Escalation During JAR Extraction
Title Privilege Escalation
First Time appeared Zohocorp
Zohocorp manageengine Endpoint Central
Weaknesses CWE-269
CPEs cpe:2.3:a:zohocorp:manageengine_endpoint_central:*:*:*:*:*:*:*:*
Vendors & Products Zohocorp
Zohocorp manageengine Endpoint Central
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L'}


Subscriptions

Zohocorp Manageengine Endpoint Central
cve-icon MITRE

Status: PUBLISHED

Assigner: Zohocorp

Published:

Updated: 2026-09-08T15:08:12.949Z

Reserved: 2026-08-21T07:48:51.328Z

Link: CVE-2026-77697

cve-icon Vulnrichment

Updated: 2026-09-08T15:08:08.236Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-07T11:17:35.687

Modified: 2026-09-08T18:35:10.323

Link: CVE-2026-77697

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T14:30:17Z

Weaknesses
  • CWE-269

    Improper Privilege Management