Junglewise Threat Intelligence

CVE-2026-6788: WatchGuard Agent uncontrolled search path in Windows

CVE-2026-6788 · Severity: high · CVSS 7.8 · Published 2026-05-06

Technologies: Watchguard Agent (Windows). Vendors: Watchguard.

Executive brief

A vulnerability in the WatchGuard Agent for Windows could allow a local user with limited permissions to gain full administrative control over the system. The WatchGuard Agent is a management tool used to monitor and secure endpoints; an exploit could allow an attacker to bypass security controls, access sensitive data, or disrupt operations. This issue is resolved in version 1.25.03.0000.

Technical details

An uncontrolled search path element (CWE-427) vulnerability exists in the WatchGuard Agent on Windows. This flaw allows a local attacker with low privileges to place a malicious file in a directory searched by the agent service, leading to the execution of arbitrary code with SYSTEM privileges. The vulnerability is often chained with other agent service flaws to achieve full local privilege escalation. The issue is fixed in WatchGuard Agent version 1.25.03.0000.

Affected products

  • WatchGuard Agent (Windows) versions before 1.25.03.0000

Timeline

  • 2026-05-06: disclosed
  • 2026-05-06: advisory: WatchGuard published advisory WGSA-2026-00013
  • 2026-05-06: patched: Fixed in version 1.25.03.0000

References

Related threats