CVE-2026-78604

Incorrect Permission Assignment for Critical Resource (CWE-732) in Elastic Agent can lead to local privilege escalation via Replace Binaries (CAPEC-642). On Windows systems where Elastic Agent is installed in unprivileged mode, resources used by the agent service are created with access controls broader than required. A local user could take advantage of this to cause the service to execute code of their choosing, ultimately obtaining SYSTEM-level privileges on the host.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:elastic:elastic_agent:*:*:*:*:*:*:*:*
cpe:2.3:a:elastic:elastic_agent:*:*:*:*:*:*:*:*
cpe:2.3:a:elastic:elastic_agent:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-09-02 15:17

Updated : 2026-09-04 16:44


NVD link : CVE-2026-78604

Mitre link : CVE-2026-78604

CVE.ORG link : CVE-2026-78604


JSON object : View

Products Affected

elastic

  • elastic_agent
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource