Description
A local privilege escalation vulnerability in the WatchGuard Mobile VPN with SSL client for Windows allows a local attacker to escalate their privileges to NT AUTHORITY\SYSTEM on the machine where the client is installed.

This issue affects the Mobile VPN with SSL client for Windows up to and including 2026.2.
Published: 2026-07-02
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a local privilege escalation flaw in the WatchGuard Mobile VPN with SSL client for Windows. It allows a local attacker to gain NT AUTHORITY\\SYSTEM privileges on the machine where the client runs. This elevation can let the attacker execute arbitrary code, modify system settings, and otherwise fully control the host. The weakness is CWE‑732: Incorrect Permissions Assignment, indicating that the flaw involves incorrect assignment of file or resource permissions.

Affected Systems

The flaw affects the Mobile VPN with SSL client for Windows up to and including version 2026.2. The product is part of the WatchGuard Fireware OS suite. A Windows system that has the vulnerable client installed is at risk. The vulnerability is local in nature, meaning the attacker must have local access to the machine to trigger it. Because the threat actor can exercise the flaw without network connectivity.

Risk and Exploitability

The CVSS base score of 7.3 indicates a high severity vulnerability, but the EPSS score of less than 1% indicates a low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV local; an attacker must have access to the client’s installation directory or be able to execute code in that environment. Once exploited, the attacker can immediately attain full SYSTEM privileges on the host, enabling arbitrary code execution, persistence, and lateral movement. Because the flaw can be triggered with local privileges, the risk is moderate to high in environments where the client is widely deployed and local accounts have significant permissions.

Generated by OpenCVE AI on August 1, 2026 at 20:57 UTC.

Remediation

Vendor Solution

Mobile VPN with SSL Client 2026.2.1


OpenCVE Recommended Actions

  • Apply the latest update to the WatchGuard Mobile VPN with Windows that includes the fix.
  • If a patch is not immediately available connectivity to eliminate the local attack surface.
  • Based on the nature of the vulnerability, reviewing and tightening the file system permissions on the client’s installation directory and executable files—ensuring that only SYSTEM administrators have write access—might mitigate the risk.

Generated by OpenCVE AI on August 1, 2026 at 20:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 10 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Watchguard mobile Vpn With Ssl Client
CPEs cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.0
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:2025.1
cpe:2.3:a:watchguard:mobile_vpn_with_ssl_client:*:*:*:*:*:*:*:*
Vendors & Products Watchguard mobile Vpn With Ssl Client
References

Mon, 06 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Description A local privilege escalation vulnerability in the WatchGuard Mobile VPN with SSL client for Windows allows a local attacker to escalate their privileges to NT AUTHORITY\SYSTEM on the machine where the client is installed. This issue affects the Mobile VPN with SSL client for Windows up to and including 2026.2.
Title WatchGuard Mobile VPN with SSL Windows Client Local Privilege Escalation
First Time appeared Watchguard
Watchguard fireware Os
Weaknesses CWE-732
CPEs cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.0
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:2025.1
Vendors & Products Watchguard
Watchguard fireware Os
References
Metrics cvssV4_0

{'score': 7.3, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L'}


Subscriptions

Watchguard Firebox M270 Firebox M290 Firebox M295 Firebox M370 Firebox M390 Firebox M395 Firebox M440 Firebox M4600 Firebox M470 Firebox M4800 Firebox M495 Firebox M5600 Firebox M570 Firebox M5800 Firebox M590 Firebox M595 Firebox M670 Firebox M690 Firebox M695 Firebox Nv5 Firebox T115-w Firebox T125 Firebox T125-w Firebox T145 Firebox T145-w Firebox T15 Firebox T185 Firebox T20 Firebox T25 Firebox T35 Firebox T40 Firebox T45 Firebox T55 Firebox T70 Firebox T80 Firebox T85 Fireboxcloud Fireboxv Fireware Fireware Os Mobile Vpn With Ssl Mobile Vpn With Ssl Client
cve-icon MITRE

Status: PUBLISHED

Assigner: WatchGuard

Published:

Updated: 2026-08-10T19:13:50.664Z

Reserved: 2026-06-23T18:02:48.522Z

Link: CVE-2026-13079

cve-icon Vulnrichment

Updated: 2026-07-06T15:46:12.680Z

cve-icon NVD

Status : Modified

Published: 2026-07-03T00:16:50.630

Modified: 2026-08-10T20:17:25.973

Link: CVE-2026-13079

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T21:00:08Z

Weaknesses
  • CWE-732

    Incorrect Permission Assignment for Critical Resource