CVE-2026-78604: Elastic Agent

High severity, CVSS 7.8. EPSS: 0.1% chance of exploitation in the next 30 days.

Incorrect Permission Assignment for Critical Resource (CWE-732) in Elastic Agent can lead to local privilege escalation via Replace Binaries (CAPEC-642). On Windows systems where Elastic Agent is installed in unprivileged mode, resources used by the agent service are created with access controls broader than required. A local user could take advantage of this to cause the service to execute code of their choosing, ultimately obtaining SYSTEM-level privileges on the host.

Affected products

  • Elastic Elastic Agent: from 8.0.0, before 8.19.21 (fixed in 8.19.21); from 9.0.0, before 9.4.6 (fixed in 9.4.6); from 9.5.0, before 9.5.2 (fixed in 9.5.2)

Published 2026-09-02. Last modified 2026-09-04.