{"$schema":"https://docs.oasis-open.org/csaf/csaf/v2.1/schema/csaf.json","document":{"category":"csaf_security_advisory","csaf_version":"2.1","title":"WatchGuard Agent on Windows Local Privilege Escalation to SYSTEM via Chained Agent Service Vulnerabilities","distribution":{"tlp":{"label":"CLEAR"}},"publisher":{"category":"vendor","name":"WatchGuard PSIRT","namespace":"https://www.watchguard.com"},"tracking":{"id":"WGSA-2026-00013","status":"final","version":"3","initial_release_date":"2026-05-06T13:00:00+00:00","current_release_date":"2026-07-28T02:58:47.577222+00:00","revision_history":[{"date":"2026-05-06T13:00:00+00:00","number":"3","summary":"Initial release."}]},"references":[{"summary":"vendor-advisory","url":"https://psirt.watchguard.com/WGSA-2026-00013"},{"summary":"cve","url":"https://www.cve.org/CVERecord?id=CVE-2026-6787"},{"summary":"cve","url":"https://www.cve.org/CVERecord?id=CVE-2026-6788"}],"notes":[{"category":"summary","text":"Local privilege escalation to SYSTEM in Single WatchGuard Agent via chained agent service vulnerabilities\n\n## Affected\nThis vulnerability affects the WatchGuard Agent on Windows versions up to and including 1.25.02.0000.","title":"Summary"}]},"product_tree":{"branches":[{"category":"vendor","name":"WatchGuard","branches":[{"category":"product_name","name":"WatchGuard Agent (Windows)","branches":[{"category":"product_version_range","name":"vers >= 1.25.0, < 1.25.03.0000","product":{"name":"WatchGuard Agent (Windows) vers >= 1.25.0, < 1.25.03.0000","product_id":"CSAFPID-a98fa5de-ec99-48df-bca9-11a8f1caf792-windows"}}]}]}]},"vulnerabilities":[{"notes":[{"category":"description","text":"Local privilege escalation to SYSTEM in Single WatchGuard Agent via chained agent service vulnerabilities\n\n## Affected\nThis vulnerability affects the WatchGuard Agent on Windows versions up to and including 1.25.02.0000.","title":"Summary"}],"product_status":{"known_affected":["CSAFPID-a98fa5de-ec99-48df-bca9-11a8f1caf792-windows"]},"cve":"CVE-2026-6787","remediations":[{"category":"vendor_fix","details":"Upgrade to WatchGuard Agent 1.25.03.0000 or later.","product_ids":["CSAFPID-a98fa5de-ec99-48df-bca9-11a8f1caf792-windows"]}]},{"notes":[{"category":"description","text":"Local privilege escalation to SYSTEM in Single WatchGuard Agent via chained agent service vulnerabilities\n\n## Affected\nThis vulnerability affects the WatchGuard Agent on Windows versions up to and including 1.25.02.0000.","title":"Summary"}],"product_status":{"known_affected":["CSAFPID-a98fa5de-ec99-48df-bca9-11a8f1caf792-windows"]},"cve":"CVE-2026-6788","remediations":[{"category":"vendor_fix","details":"Upgrade to WatchGuard Agent 1.25.03.0000 or later.","product_ids":["CSAFPID-a98fa5de-ec99-48df-bca9-11a8f1caf792-windows"]}]}]}