Junglewise Threat Intelligence

CVE-2026-13079: WatchGuard Mobile VPN with SSL client privilege escalation

CVE-2026-13079 · Severity: info · CVSS 7.3 · Published 2026-07-03

Technologies: Watchguard Mobile VPN with SSL client. Vendors: Watchguard.

Executive brief

A security vulnerability exists in the WatchGuard Mobile VPN with SSL client for Windows, a tool used by employees to securely connect to corporate networks. A person with existing low-level access to a computer could exploit this flaw to gain full administrative control (SYSTEM privileges) over that machine. This could allow an attacker to bypass security controls, access sensitive local data, or install malicious software.

Technical details

A local privilege escalation vulnerability exists in the WatchGuard Mobile VPN with SSL client for Windows due to incorrect permission assignment for a critical resource (CWE-732). The flaw allows a local attacker with low-level user privileges to execute code with NT AUTHORITY\SYSTEM authority. The vulnerability is present in versions up to and including 2026.2. The issue has been resolved in version 2026.2.1. Exploitation requires local access to the target machine but does not require user interaction.

Affected products

  • WatchGuard Mobile VPN with SSL client for Windows up to and including 2026.2

Timeline

  • 2026-07-02: advisory: WatchGuard published advisory WGSA-2026-00027
  • 2026-07-02: patched: Fixed in version 2026.2.1

References

Related threats