CVE-2026-6788

HIGH

Uncontrolled search path in PluginLauncher allows SYSTEM code execution in WatchGuard Agent

Title source: cna
STIX 2.1

Description

Uncontrolled Search Path Element vulnerability in WatchGuard Agent on Windows allows Using Malicious Files.This issue affects WatchGuard Agent before 1.25.03.0000.

Scores

CVSS v3 7.8
EPSS 0.0012
EPSS Percentile 2.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-427
Status published
Products (2)
watchguard/agent < 1.25.03.0000
WatchGuard/WatchGuard Agent < 1.25.03.0000
Published May 06, 2026
Tracked Since May 06, 2026