2026-05-06 15:45CVE-2026-41288WatchGuard
PUBLISHED5.2CWE-732

WatchGuard Agent on Windows Privilege Escalation Vulnerability

Incorrect permission assignment for a resource in the patch management component of the WatchGuard Agent on Windows allows an authenticated local user to elevate their privileges to NT AUTHORITY\\SYSTEM.

Problem type

Affected products

WatchGuard

WatchGuard Agent

< 1.25.03.0000 - AFFECTED

References

GitHub Security Advisories

GHSA-8cwf-5634-rgvv

Incorrect permission assignment for a resource in the patch management component of the...

https://github.com/advisories/GHSA-8cwf-5634-rgvv

Incorrect permission assignment for a resource in the patch management component of the WatchGuard Agent on Windows allows an authenticated local user to elevate their privileges to NT AUTHORITY\SYSTEM.

JSON source

https://cveawg.mitre.org/api/cve/CVE-2026-41288
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2026-41288",
    "assignerOrgId": "5d1c2695-1a31-4499-88ae-e847036fd7e3",
    "assignerShortName": "WatchGuard",
    "dateUpdated": "2026-05-06T16:12:23.875Z",
    "dateReserved": "2026-04-20T09:57:56.546Z",
    "datePublished": "2026-05-06T15:45:43.371Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "5d1c2695-1a31-4499-88ae-e847036fd7e3",
        "shortName": "WatchGuard",
        "dateUpdated": "2026-05-06T15:45:43.371Z"
      },
      "title": "WatchGuard Agent on Windows Privilege Escalation Vulnerability",
      "descriptions": [
        {
          "lang": "en",
          "value": "Incorrect permission assignment for a resource in the patch management component of the WatchGuard Agent on Windows allows an authenticated local user to elevate their privileges to NT AUTHORITY\\\\SYSTEM.",
          "supportingMedia": [
            {
              "type": "text/html",
              "base64": false,
              "value": "Incorrect permission assignment for a resource in the patch management component of the WatchGuard Agent on Windows allows an authenticated local user to elevate their privileges to NT AUTHORITY\\\\SYSTEM.<p></p>"
            }
          ]
        }
      ],
      "affected": [
        {
          "vendor": "WatchGuard",
          "product": "WatchGuard Agent",
          "platforms": [
            "Windows"
          ],
          "defaultStatus": "unaffected",
          "versions": [
            {
              "version": "0",
              "status": "affected",
              "versionType": "custom",
              "lessThan": "1.25.03.0000"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "CWE-732 Incorrect Permission Assignment for Critical Resource",
              "cweId": "CWE-732",
              "type": "CWE"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://www.watchguard.com/wgrd-psirt/advisory/WGSA-2026-00011"
        }
      ],
      "impacts": [
        {
          "capecId": "CAPEC-17",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-17 Using Malicious Files"
            }
          ]
        }
      ],
      "metrics": [
        {
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ]
    },
    "adp": [
      {
        "providerMetadata": {
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP",
          "dateUpdated": "2026-05-06T16:12:23.875Z"
        },
        "title": "CISA ADP Vulnrichment",
        "metrics": [
          {}
        ]
      }
    ]
  }
}