CVE-2026-78604
Analyzed Analyzed - Analysis Complete

Incorrect Permission Assignment in Elastic Agent Leads to Privilege Escalation

Vulnerability report for CVE-2026-78604, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-02

Last updated on: 2026-09-04

Assigner: Elastic

Description

Incorrect Permission Assignment for Critical Resource (CWE-732) in Elastic Agent can lead to local privilege escalation via Replace Binaries (CAPEC-642). On Windows systems where Elastic Agent is installed in unprivileged mode, resources used by the agent service are created with access controls broader than required. A local user could take advantage of this to cause the service to execute code of their choosing, ultimately obtaining SYSTEM-level privileges on the host.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-02
Last Modified
2026-09-04
Generated
2026-09-15
AI Q&A
2026-09-02
EPSS Evaluated
2026-09-14
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
elastic elastic_agent From 8.0.0 (inc) to 8.19.21 (exc)
elastic elastic_agent From 9.0.0 (inc) to 9.4.6 (exc)
elastic elastic_agent From 9.5.0 (inc) to 9.5.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-732 The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a local privilege escalation vulnerability in Elastic Agent on Windows systems. It occurs when the agent is installed in unprivileged mode, causing critical resources to have overly permissive access controls. A local attacker can exploit this to manipulate the agent service into executing arbitrary code, gaining SYSTEM-level privileges on the host.

Detection Guidance

To detect this vulnerability, check the installed Elastic Agent version on Windows systems using: 'elastic-agent version'. If the version is 8.19.20 or below (8.x), 9.4.5 or below (9.x), or 9.5.1 or below (9.x), the system is vulnerable.

Impact Analysis

If you use Elastic Agent on Windows in unprivileged mode, a local attacker could exploit this flaw to gain full control over your system. This could allow them to install malware, steal data, or perform other malicious actions with SYSTEM privileges.

Compliance Impact

This vulnerability primarily impacts compliance by increasing the risk of unauthorized SYSTEM-level access on Windows systems where Elastic Agent is installed in unprivileged mode. Unauthorized privilege escalation could lead to data breaches, unauthorized data access, or manipulation, which are critical violations under GDPR and HIPAA. The flaw enables attackers to gain full control over affected systems, potentially exposing sensitive personal or health data.

Mitigation Strategies

Upgrade Elastic Agent to versions 8.19.21, 9.4.6, or 9.5.2. If upgrading is not possible, avoid unprivileged installations on Windows or switch to privileged mode to mitigate the risk.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78604. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart