CVE-2026-78604
Received Received - Intake

Incorrect Permission Assignment in Elastic Agent Leads to Privilege Escalation

Vulnerability report for CVE-2026-78604, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-02

Last updated on: 2026-09-02

Assigner: Elastic

Description

Incorrect Permission Assignment for Critical Resource (CWE-732) in Elastic Agent can lead to local privilege escalation via Replace Binaries (CAPEC-642). On Windows systems where Elastic Agent is installed in unprivileged mode, resources used by the agent service are created with access controls broader than required. A local user could take advantage of this to cause the service to execute code of their choosing, ultimately obtaining SYSTEM-level privileges on the host.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-02
Last Modified
2026-09-02
Generated
2026-09-02
AI Q&A
2026-09-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
elastic elastic_agent *
elastic elastic_agent to 8.19.21 (exc)
elastic elastic_agent to 9.4.6 (exc)
elastic elastic_agent to 9.5.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-732 The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a local privilege escalation vulnerability in Elastic Agent on Windows systems. It occurs when the agent is installed in unprivileged mode, causing critical resources to have overly permissive access controls. A local attacker can exploit this to manipulate the agent service into executing arbitrary code, gaining SYSTEM-level privileges on the host.

Detection Guidance

To detect this vulnerability, check the installed Elastic Agent version on Windows systems using: 'elastic-agent version'. If the version is 8.19.20 or below (8.x), 9.4.5 or below (9.x), or 9.5.1 or below (9.x), the system is vulnerable.

Impact Analysis

If you use Elastic Agent on Windows in unprivileged mode, a local attacker could exploit this flaw to gain full control over your system. This could allow them to install malware, steal data, or perform other malicious actions with SYSTEM privileges.

Mitigation Strategies

Upgrade Elastic Agent to versions 8.19.21, 9.4.6, or 9.5.2. If upgrading is not possible, avoid unprivileged installations on Windows or switch to privileged mode to mitigate the risk.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78604. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart