CVE-2026-57909 PUBLISHED

WatchGuard Agent path traversal allows unauthenticated remote code execution

Assigner: WatchGuard
Reserved: 26.06.2026 Published: 25.08.2026 Updated: 26.08.2026

A path traversal vulnerability in WatchGuard Agent allows a remote, unauthenticated attacker on an adjacent network to execute arbitrary code on an affected system.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CVSS Score: 9.4

Product Status

Vendor WatchGuard
Product WatchGuard Agent
Versions Default: affected
  • affected from 0 to 1.25.13.0000 (excl.)

Exploits

WatchGuard is not aware of any exploitation of this vulnerability in the wild.

Solutions

WatchGuard Agent 1.25.13.0000

Credits

  • R31n finder

References

Problem Types

  • CWE-306 CWE
  • CWE-94 CWE