Description
Zohocorp ManageEngine Endpoint Central versions below 11.5.2600.15 are vulnerable to Privilege Escalation Due to Outdated Component
Published: 2026-09-07
Score: 6.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Zohocorp ManageEngine Endpoint Central versions below 11.5.2600.15 are vulnerable to privilege escalation due to an outdated component. The flaw allows an attacker who can manipulate the outdated component to gain higher privileges within the system. This weakness corresponds to CWE‑269, Incorrect Privilege Assignment, and could compromise confidentiality, integrity, or availability of the affected environment if elevated privileges are used for malicious actions.

Affected Systems

Affected systems are Zohocorp ManageEngine Endpoint Central installations running any version prior to 11.5.2600.15. The exact affected components are not enumerated beyond the overall product, but the vulnerability is triggered by the presence of an outdated dependency that is still in use. All customers who have not upgraded past the 11.5.2600.15 release are potentially exposed.

Risk and Exploitability

The CVSS base score of 6.3 indicates moderate severity, and the absence of an EPSS score means there is currently no publicly recorded exploitation data. The vulnerability is not listed in the CISA KEV catalog, so no confirmed active exploits are known as of the latest advisory. Attackers would likely need local or authenticated access to the Endpoint Central server to influence the outdated component, then leverage the privilege escalation to increase their rights. Once elevated, an attacker could pivot within the network or compromise additional systems. Due to the lack of remote exploitability data, the risk mainly applies to environments where the product is exposed to potentially untrusted users.

Generated by OpenCVE AI on September 7, 2026 at 13:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to version 11.5.2600.15 or later, ensuring the vulnerable component is removed.
  • If an upgrade is not immediately possible, remove or disable the identified outdated component so that it cannot be used to elevate privileges.
  • Restart the ManageEngine Endpoint Central services to load the updated binaries.

Generated by OpenCVE AI on September 7, 2026 at 13:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 07 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 07 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Description Zohocorp ManageEngine Endpoint Central versions below 11.5.2600.15 are vulnerable to Privilege Escalation Due to Outdated Component
Title Privilege Escalation
First Time appeared Zohocorp
Zohocorp manageengine Endpoint Central
Weaknesses CWE-269
CPEs cpe:2.3:a:zohocorp:manageengine_endpoint_central:*:*:*:*:*:*:*:*
Vendors & Products Zohocorp
Zohocorp manageengine Endpoint Central
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L'}


Subscriptions

Zohocorp Manageengine Endpoint Central
cve-icon MITRE

Status: PUBLISHED

Assigner: Zohocorp

Published:

Updated: 2026-09-07T10:56:42.941Z

Reserved: 2026-09-04T12:20:43.905Z

Link: CVE-2026-85640

cve-icon Vulnrichment

Updated: 2026-09-07T10:56:39.623Z

cve-icon NVD

Status : Received

Published: 2026-09-07T11:17:37.613

Modified: 2026-09-07T11:17:37.613

Link: CVE-2026-85640

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T14:30:17Z

Weaknesses
  • CWE-269

    Improper Privilege Management