CVE-2026-78604
largeInsecure File Permissions Enable Local Privilege Escalation in Elastic Agent on Windows
Elastic Agent on Windows, when installed in unprivileged mode, creates resources used by the agent service with access-control permissions broader than required (CWE-732, incorrect permission assignment for critical resource). A local attacker with low privileges can exploit this by replacing the agent service's binaries (CAPEC-642), causing the service to execute attacker-chosen code. Because the agent service runs in a privileged context, this results in full SYSTEM-level privileges on the affected Windows host. Only Windows systems where Elastic Agent was installed in unprivileged mode are affected, per the vendor description. There is currently no known public proof-of-concept, the issue is not in CISA's KEV, and EPSS estimates only about a 0.1% probability of exploitation in the next 30 days.
What to do: Inventory Windows endpoints running Elastic Agent and identify which were installed in unprivileged mode, as those are the affected hosts. Upgrade those agents to the patched release cited in Elastic's security advisory (Elastic is the CNA; check elastic.co/security for the exact fixed version). As an interim mitigation, verify and restrict ACLs on the Elastic Agent installation directory and service resources so unprivileged users cannot write to or replace the service binaries.
| Elastic Agent | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect Permission Assignment for Critical Resource (CWE-732) in Elastic Agent can lead to local privilege escalation via Replace Binaries (CAPEC-642). On Windows systems where Elastic Agent is installed in unprivileged mode, resources used by the agent service are created with access controls broader than required. A local user could take advantage of this to cause the service to execute code of their choosing, ultimately obtaining SYSTEM-level privileges on the host.
- Vendors
- elastic
- Products
- elastic agent
- Weakness
- CWE-732
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.