WGSA-2026-00013#
WatchGuard Agent on Windows Local Privilege Escalation to SYSTEM via Chained Agent Service Vulnerabilities
Summary #
Local privilege escalation to SYSTEM in Single WatchGuard Agent via chained agent service vulnerabilities
## Affected This vulnerability affects the WatchGuard Agent on Windows versions up to and including 1.25.02.0000.
CVE identifiers #
| CVE ID | Description | CVSS |
|---|---|---|
| CVE-2026-6787 | Use of Hard-coded Cryptographic Key vulnerability in WatchGuard Agent on Windows allows Inclusion of Code in Existing Process.This issue affects WatchGuard Agent: before 1.25.03.0000. | 8.5 |
| CVE-2026-6788 | Uncontrolled Search Path Element vulnerability in WatchGuard Agent on Windows allows Using Malicious Files.This issue affects WatchGuard Agent before 1.25.03.0000. | 8.5 |
Product status #
| Product | Affected | Not affected |
|---|---|---|
| WatchGuard Agent | ||
| Windows | >= 1.25.0, < 1.25.03.0000 | >= 1.25.03.0000 |
Solution #
- This vulnerability is resolved in the WatchGuard Agent on Windows version 1.25.03.0000.