{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-13079","assignerOrgId":"5d1c2695-1a31-4499-88ae-e847036fd7e3","state":"PUBLISHED","assignerShortName":"WatchGuard","dateReserved":"2026-06-23T18:02:48.522Z","datePublished":"2026-07-02T23:07:30.489Z","dateUpdated":"2026-08-10T19:13:50.664Z"},"containers":{"cna":{"providerMetadata":{"orgId":"5d1c2695-1a31-4499-88ae-e847036fd7e3","shortName":"WatchGuard","dateUpdated":"2026-08-10T19:13:50.664Z"},"title":"WatchGuard Mobile VPN with SSL Windows Client Local Privilege Escalation","descriptions":[{"lang":"en","value":"A local privilege escalation vulnerability in the WatchGuard Mobile VPN with SSL client for Windows allows a local attacker to escalate their privileges to NT AUTHORITY\\SYSTEM on the machine where the client is installed.\n\nThis issue affects the Mobile VPN with SSL client for Windows up to and including 2026.2."}],"affected":[{"vendor":"WatchGuard","product":"Mobile VPN with SSL Client","versions":[{"status":"affected","version":"12.0","versionType":"semver","lessThan":"2026.2.1"}],"defaultStatus":"unaffected","platforms":["Windows"]}],"references":[{"url":"https://psirt.watchguard.com/CVE-2026-13079","tags":["vendor-advisory"]},{"url":"https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00027","tags":["vendor-advisory"]}],"cpeApplicability":[{"operator":"OR","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:watchguard:mobile_vpn_with_ssl_client:*:*:*:*:*:*:*:*","versionStartIncluding":"12.0","versionEndExcluding":"2026.2.1"}]}]}],"metrics":[{"cvssV4_0":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L","baseScore":7.3,"baseSeverity":"HIGH"}}],"problemTypes":[{"descriptions":[{"lang":"en","description":"CWE-732","type":"CWE","cweId":"CWE-732"}]}],"credits":[{"lang":"en","value":"Paul Arzelier, Truesec","type":"finder"}],"solutions":[{"lang":"en","value":"Mobile VPN with SSL Client 2026.2.1","supportingMedia":[{"type":"text/html","base64":false,"value":"Mobile VPN with SSL Client 2026.2.1"}]}],"exploits":[{"lang":"en","value":"WatchGuard is not aware of any exploitation of this vulnerability in the wild.","supportingMedia":[{"type":"text/html","base64":false,"value":"WatchGuard is not aware of any exploitation of this vulnerability in the wild."}]}],"datePublic":"2026-07-02T23:07:30.489Z"},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-07-06T00:00:00+00:00","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3","id":"CVE-2026-13079"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-07-07T03:56:26.251Z"}}]}}