CVE-2026-41288

WatchGuard Agent on Windows Privilege Escalation Vulnerability

High 7.3 CVSS v4.0 › Published 2026-05-06Updated 2026-08-10

Summary #

Incorrect permission assignment for a resource in the patch management component of the WatchGuard Agent on Windows allows an authenticated local user to elevate their privileges to NT AUTHORITY\\SYSTEM.

Product status #

ProductAffectedNot affected
WatchGuard Agent>= 1.0.0.0, < 1.25.03.0000>= 1.25.03.0000

Weakness Type and Impact #

  • CWECWE-732Incorrect Permission Assignment for Critical Resource
  • CAPECCAPEC-17Using Malicious Files

Exploitation Status #

WatchGuard is not aware of any exploitation of this vulnerability in the wild.

Solution #

WatchGuard Agent 1.25.03.0000

References #