CVE-2026-41288
Incorrect Permission Assignment in WatchGuard Agent for Windows Leads to Privilege Escalation
Publication date: 2026-05-06
Last updated on: 2026-05-06
Assigner: WatchGuard Technologies, Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| watchguard | agent | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-732 | The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability involves incorrect permission assignment in the patch management component of the WatchGuard Agent on Windows. It allows an authenticated local user to elevate their privileges to NT AUTHORITY\SYSTEM, which is the highest level of privilege on a Windows system.
How can this vulnerability impact me? :
An attacker who is already authenticated locally on the affected system can exploit this vulnerability to gain SYSTEM-level privileges. This means they could perform any action on the system, including installing software, changing configurations, accessing sensitive data, or disabling security controls.