Description
A Cross-Site Scripting (XSS) vulnerability in the WatchGuard Dimension Backup Historical Data feature allows an authenticated administrator user to execute arbitrary JavaScript in another user's browser.
Published: 2026-08-27
Score: 5.1 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a stored cross‑site scripting flaw in the Backup Historical Data feature of WatchGuard Dimension. An authenticated administrator can embed arbitrary JavaScript into historical data entries, and when other users view that data the script executes in their browser. Because the code runs with the victim’s privileges, it can steal session cookies, capture credentials, or perform actions on the user’s behalf. The weakness is classified as CWE‑79.

Affected Systems

All versions of WatchGuard Dimension that have not been upgraded to the patched release 2.3.1 are susceptible. The flaw is triggered through the Backup Historical Data interface, which is available to any user with administrator rights.

Risk and Exploitability

The CVSS score of 5.1 reflects a moderate severity; an EPSS score is not supplied and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated administrator account, limiting the initial attack surface to privileged users. Once an attacker creates or modifies a malicious entry, any other user who views that data in a web browser is exposed to the injected script. The likely attack vector is internal, relying on administrative access, and the potential impact includes session hijacking, data theft, or further privilege escalation within the affected system.

Generated by OpenCVE AI on August 28, 2026 at 07:48 UTC.

Remediation

Vendor Solution

Dimension 2.3.1


OpenCVE Recommended Actions

  • Upgrade WatchGuard Dimension to version 2.3.1 or later to remove the stored‑XSS flaw.
  • Limit the use of the Backup Historical Data feature to a small group of trusted administrative accounts and enforce least‑privilege access controls.
  • If a patch cannot be applied immediately, consider disabling the feature or removing existing historical data entries to eliminate the stored script source while monitoring usage log events for suspicious activity.

Generated by OpenCVE AI on August 28, 2026 at 07:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description A Cross-Site Scripting (XSS) vulnerability in the WatchGuard Dimension Backup Historical Data feature allows an authenticated administrator user to execute arbitrary JavaScript in another user's browser.
Title Dimension Stored XSS via Backup Historical Data Feature
First Time appeared Watchguard
Watchguard dimension
Weaknesses CWE-79
CPEs cpe:2.3:a:watchguard:dimension:*:*:*:*:*:*:*:*
Vendors & Products Watchguard
Watchguard dimension
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Watchguard Dimension
cve-icon MITRE

Status: PUBLISHED

Assigner: WatchGuard

Published:

Updated: 2026-08-27T23:26:31.597Z

Reserved: 2026-08-23T20:50:31.029Z

Link: CVE-2026-78195

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-28T02:16:23.080

Modified: 2026-08-28T02:16:23.080

Link: CVE-2026-78195

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T08:00:13Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')