Description
Improper authentication in the WatchGuard Agent allows an unauthenticated attacker with network access to cause the agent to execute arbitrary code with elevated privileges.
Published: 2026-08-25
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The WatchGuard Agent suffers an improper authentication flaw. An attacker that can reach the agent over the network, without needing prior credentials, can trigger the agent to run arbitrary code with elevated privileges. The flaw enables full control over the host, allowing data theft, lateral movement, and additional exploitation. The weakness corresponds to CWE-306, CWE-347, and CWE-494.

Affected Systems

All installations of WatchGuard Agent before the vendor‑released patches (1.17.02.0000, 1.17.21.0000, 1.25.13.0000) are affected. The vulnerability applies to the agent component that listens for remote management commands; any deployment with network exposure to untrusted hosts without authentication is at risk.

Risk and Exploitability

The CVSS base score of 9.3 marks the issue as critical. Although no EPSS value is available, the absence of an EPSS figure suggests either limited data or low exploitation probability, but the implication remains severe. Since it is not listed in the CISA KEV catalog, the risk relies on the attacker’s ability to reach the agent. With network access and no authentication required, the attack vector is straightforward, making the vulnerability a high‑priority target for threat actors.

Generated by OpenCVE AI on August 25, 2026 at 13:23 UTC.

Remediation

Vendor Solution

WatchGuard Agent 1.17.02.0000, WatchGuard Agent 1.17.21.0000, WatchGuard Agent 1.25.13.0000


OpenCVE Recommended Actions

  • Upgrade WatchGuard Agent to one of the patched releases: 1.17.02.0000, 1.17.21.0000, or 1.25.13.0000.
  • Restrict network access to the agent by placing it behind a firewall or using VPNs, ensuring only trusted hosts can reach it.
  • Verify that authentication mechanisms are enforced and that the agent no longer accepts unauthenticated connections; monitor logs for suspicious activity.

Generated by OpenCVE AI on August 25, 2026 at 13:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 12:00:00 +0000

Type Values Removed Values Added
Description Improper authentication in the WatchGuard Agent allows an unauthenticated attacker with network access to cause the agent to execute arbitrary code with elevated privileges.
Title WatchGuard Agent improper authentication allows unauthenticated remote code execution
First Time appeared Watchguard
Watchguard watchguard Agent
Weaknesses CWE-306
CWE-347
CWE-494
CPEs cpe:2.3:a:watchguard:watchguard_agent:*:*:*:*:*:*:*:*
Vendors & Products Watchguard
Watchguard watchguard Agent
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Watchguard Watchguard Agent
cve-icon MITRE

Status: PUBLISHED

Assigner: WatchGuard

Published:

Updated: 2026-08-25T12:53:13.695Z

Reserved: 2026-06-26T09:41:49.464Z

Link: CVE-2026-57910

cve-icon Vulnrichment

Updated: 2026-08-25T12:53:09.891Z

cve-icon NVD

Status : Received

Published: 2026-08-25T12:16:24.773

Modified: 2026-08-25T13:19:24.810

Link: CVE-2026-57910

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T13:30:17Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function

  • CWE-347

    Improper Verification of Cryptographic Signature

  • CWE-494

    Download of Code Without Integrity Check