CVE-2026-57910 PUBLISHED

WatchGuard Agent improper authentication allows unauthenticated remote code execution

Assigner: WatchGuard
Reserved: 26.06.2026 Published: 25.08.2026 Updated: 25.08.2026

Improper authentication in the WatchGuard Agent allows an unauthenticated attacker with network access to cause the agent to execute arbitrary code with elevated privileges.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor WatchGuard
Product WatchGuard Agent
Versions Default: unaffected
  • affected from 0 to 1.25.13.0000 (excl.)

Exploits

WatchGuard is not aware of any exploitation of this vulnerability in the wild.

Solutions

WatchGuard Agent 1.17.02.0000, WatchGuard Agent 1.17.21.0000, WatchGuard Agent 1.25.13.0000

References

Problem Types

  • CWE-306 CWE
  • CWE-347 CWE
  • CWE-494 CWE