CVE-2026-13079

EUVD-2026-41460
A local privilege escalation vulnerability in the WatchGuard Mobile VPN with SSL client for Windows allows a local attacker to escalate their privileges to NT AUTHORITY\SYSTEM on the machine where the client is installed.

This issue affects the Mobile VPN with SSL client for Windows up to and including 2026.2.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 3.91%
Affected Products (NVD)
VendorProductVersion
watchguardmobile_vpn_with_ssl
𝑥
< 2026.2.1
watchguardfireware
12.0.0 ≤
𝑥
< 12.12.1
watchguardfireware
2025.1 ≤
𝑥
< 2026.2.1
watchguardfireware
12.5 ≤
𝑥
≤ 12.5.18
𝑥
= Vulnerable software versions