Description
A missing authentication vulnerability in the Kernel Memory Access Driver (PSKMAD) used by WatchGuard endpoint security products allows a local, authenticated attacker to bypass the driver's access-control handshake and issue arbitrary privileged commands to the driver, resulting in disclosure of kernel and process memory.
Published: 2026-10-01
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: Arbitrary kernel memory disclosure and privilege escalation
Action: Patch Immediately
AI Analysis

Impact

The vulnerability exposes a missing authentication check in the Kernel Memory Access Driver (PSKMAD) used by WatchGuard Endpoint Security. A locally authenticated user can bypass the driver’s access‑control handshake and send arbitrary privileged commands to the driver, causing disclosure of kernel and process memory. This results in a high‑severity compromise of confidentiality and gives an attacker a powerful foothold within the system.

Affected Systems

The affected product is WatchGuard Endpoint Security. The vulnerability resides in the PSKMAD driver supplied with that product. No specific product versions are listed in the CNA data, so all installations of this driver are potentially vulnerable until a vendor update is applied.

Risk and Exploitability

The CVSS score of 9.3 indicates critical risk. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog, but the lack of remote reachability limits exposure to environments where an attacker already has local, authenticated access. Nevertheless, given the kernel‑level impact, the potential for system compromise remains high, so the vulnerability should be treated as a priority remediation item.

Generated by OpenCVE AI on October 1, 2026 at 17:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest vendor patch or update for WatchGuard Endpoint Security that addresses the PSKMAD missing authentication issue.
  • If a patch is not yet available, disable the Kernel Memory Access Driver (PSKMAD) by removing or renaming the driver file or by disabling the feature in the product configuration, to prevent local users from interacting with it.
  • Enforce the principle of least privilege for local accounts, ensuring that only trusted users or services have the necessary permissions to load or communicate with kernel drivers.

Generated by OpenCVE AI on October 1, 2026 at 17:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Description A missing authentication vulnerability in the Kernel Memory Access Driver (PSKMAD) used by WatchGuard endpoint security products allows a local, authenticated attacker to bypass the driver's access-control handshake and issue arbitrary privileged commands to the driver, resulting in disclosure of kernel and process memory.
Title WatchGuard Endpoint Security Missing Authentication in Kernel Memory Access Driver Allows Arbitrary Kernel Memory Access
First Time appeared Watchguard
Watchguard endpoint Security
Weaknesses CWE-306
CWE-798
CPEs cpe:2.3:a:watchguard:endpoint_security:*:*:*:*:*:*:*:*
Vendors & Products Watchguard
Watchguard endpoint Security
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Watchguard Endpoint Security
cve-icon MITRE

Status: PUBLISHED

Assigner: WatchGuard

Published:

Updated: 2026-10-01T16:31:34.559Z

Reserved: 2026-06-23T17:29:47.454Z

Link: CVE-2026-13043

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-01T17:17:21.290

Modified: 2026-10-01T17:17:21.290

Link: CVE-2026-13043

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T18:00:08Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function

  • CWE-798

    Use of Hard-coded Credentials