CVE-2026-78604 PUBLISHED

Incorrect Permission Assignment for Critical Resource in Elastic Agent Leading to Local Privilege Escalation to SYSTEM

Assigner: elastic
Reserved: 24.08.2026 Published: 02.09.2026 Updated: 02.09.2026

Incorrect Permission Assignment for Critical Resource (CWE-732) in Elastic Agent can lead to local privilege escalation via Replace Binaries (CAPEC-642). On Windows systems where Elastic Agent is installed in unprivileged mode, resources used by the agent service are created with access controls broader than required. A local user could take advantage of this to cause the service to execute code of their choosing, ultimately obtaining SYSTEM-level privileges on the host.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 7.8

Product Status

Vendor Elastic
Product Elastic Agent
Versions Default: unaffected
  • affected from 8.0.0 to 8.19.20 (incl.)
  • affected from 9.0.0 to 9.4.5 (incl.)
  • affected from 9.5.0 to 9.5.1 (incl.)

References

Problem Types

  • CWE-732 Incorrect Permission Assignment for Critical Resource CWE

Impacts

  • CAPEC-642 Replace Binaries