CVE-2026-6788

Uncontrolled search path in PluginLauncher allows SYSTEM code execution in WatchGuard Agent

High 8.5 CVSS v4.0 › Published 2026-05-06Updated 2026-08-10

Summary #

Uncontrolled Search Path Element vulnerability in WatchGuard Agent on Windows allows Using Malicious Files.

Product status #

ProductAffectedNot affected
WatchGuard Agent>= 1.0.0.0, < 1.25.03.0000>= 1.25.03.0000

Weakness Type and Impact #

  • CWECWE-427Uncontrolled Search Path Element
  • CAPECCAPEC-17Using Malicious Files

Exploitation Status #

WatchGuard is not aware of any exploitation of this vulnerability in the wild.

Solution #

WatchGuard Agent 1.25.03.0000

References #