Vulnerability Description
Incorrect Permission Assignment for Critical Resource (CWE-732) in Elastic Agent can lead to local privilege escalation via Replace Binaries (CAPEC-642). On Windows systems where Elastic Agent is installed in unprivileged mode, resources used by the agent service are created with access controls broader than required. A local user could take advantage of this to cause the service to execute code of their choosing, ultimately obtaining SYSTEM-level privileges on the host.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Elastic | Elastic Agent | >= 8.0.0, < 8.19.21 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-78604?
CVE-2026-78604 is a vulnerability with a CVSS score of 7.8 (HIGH). Incorrect Permission Assignment for Critical Resource (CWE-732) in Elastic Agent can lead to local privilege escalation via Replace Binaries (CAPEC-642). On Windows systems where Elastic Agent is inst...
How severe is CVE-2026-78604?
CVE-2026-78604 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-78604?
Check the references section above for vendor advisories and patch information. Affected products include: Elastic Elastic Agent.