Description
Rejecting as a duplicate of CVE-2026-78047
Published: 2026-08-27
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Rejecting as a duplicate of CVE-2026-78047

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade WatchGuard Dimension to version 2.3.1 or later to remove the stored‑XSS flaw.
  • Limit the use of the Backup Historical Data feature to a small group of trusted administrative accounts and enforce least‑privilege access controls.
  • If a patch cannot be applied immediately, consider disabling the feature or removing existing historical data entries to eliminate the stored script source while monitoring usage log events for suspicious activity.

Generated by OpenCVE AI on August 28, 2026 at 07:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References

No reference.

History

Thu, 03 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X'}


Fri, 28 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Description A Cross-Site Scripting (XSS) vulnerability in the WatchGuard Dimension Backup Historical Data feature allows an authenticated administrator user to execute arbitrary JavaScript in another user's browser. Rejecting as a duplicate of CVE-2026-78047
Title Dimension Stored XSS via Backup Historical Data Feature
CPEs cpe:2.3:a:watchguard:dimension:*:*:*:*:*:*:*:*
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X'}


Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description A Cross-Site Scripting (XSS) vulnerability in the WatchGuard Dimension Backup Historical Data feature allows an authenticated administrator user to execute arbitrary JavaScript in another user's browser.
Title Dimension Stored XSS via Backup Historical Data Feature
First Time appeared Watchguard
Watchguard dimension
Weaknesses CWE-79
CPEs cpe:2.3:a:watchguard:dimension:*:*:*:*:*:*:*:*
Vendors & Products Watchguard
Watchguard dimension
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Watchguard Dimension
cve-icon MITRE

Status: REJECTED

Assigner: WatchGuard

Published:

Updated: 2026-08-28T14:33:35.260Z

Reserved: 2026-08-23T20:50:31.029Z

Link: CVE-2026-78195

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Rejected

Published: 2026-08-28T02:16:23.080

Modified: 2026-09-03T05:13:07.860

Link: CVE-2026-78195

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T08:00:13Z

Weaknesses

No weakness.