Skip to content
ElasticCVE-2026-78604

Elastic Agent: insecure permissions

High7.8CVE-2026-78604 · Published Sep 2, 2026 · updated Sep 4, 2026

Incorrect Permission Assignment for Critical Resource (CWE-732) in Elastic Agent can lead to local privilege escalation via Replace Binaries (CAPEC-642). On Windows systems where Elastic Agent is installed in unprivileged mode, resources used by the agent service are created with access controls broader than required. A local user could take advantage of this to cause the service to execute code of their choosing, ultimately obtaining SYSTEM-level privileges on the host.

Elastic advisory

Affected versions

PackageAffectedFixed in
Elastic Agent
Product
>= 8.0.0, <= 8.19.20No fix yet
>= 9.0.0, <= 9.4.5No fix yet
>= 9.5.0, <= 9.5.1No fix yet
Details and references

More Elastic advisories

All Elastic
Advisory
Elastic Kibana: improper authorization
Medium4.3Sep 2
Elastic Kibana: path traversal
Medium6.5Sep 2
Elastic Eck Operator: incomplete cleanup
Low3.5Sep 2
Elastic Kibana: missing authorization
Medium5.5Sep 2
Elastic Maps Server: path traversal
Medium5.3Sep 2
Elastic Eck Operator: improper authorization
Medium5.4Sep 2

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.