WGSA-2026-00013

WatchGuard Agent on Windows Local Privilege Escalation to SYSTEM via Chained Agent Service Vulnerabilities

High Published 2026-05-06Updated 2026-07-28

Summary #

Local privilege escalation to SYSTEM in Single WatchGuard Agent via chained agent service vulnerabilities

## Affected This vulnerability affects the WatchGuard Agent on Windows versions up to and including 1.25.02.0000.

CVE identifiers #

CVE IDDescriptionCVSS
CVE-2026-6787 Use of Hard-coded Cryptographic Key vulnerability in WatchGuard Agent on Windows allows Inclusion of Code in Existing Process.This issue affects WatchGuard Agent: before 1.25.03.0000. 8.5
CVE-2026-6788 Uncontrolled Search Path Element vulnerability in WatchGuard Agent on Windows allows Using Malicious Files.This issue affects WatchGuard Agent before 1.25.03.0000. 8.5

Product status #

ProductAffectedNot affected
WatchGuard Agent
Windows >= 1.25.0, < 1.25.03.0000>= 1.25.03.0000

Solution #

  • This vulnerability is resolved in the WatchGuard Agent on Windows version 1.25.03.0000.

References #