CVE-2026-41288

HIGH

WatchGuard Agent on Windows Privilege Escalation Vulnerability

Title source: cna
STIX 2.1

Description

Incorrect permission assignment for a resource in the patch management component of the WatchGuard Agent on Windows allows an authenticated local user to elevate their privileges to NT AUTHORITY\\SYSTEM.

Scores

CVSS v3 7.8
EPSS 0.0010
EPSS Percentile 1.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-732
Status published
Products (2)
watchguard/agent < 1.25.03.0000
WatchGuard/WatchGuard Agent < 1.25.03.0000
Published May 06, 2026
Tracked Since May 06, 2026