Rejecting as a duplicate of CVE-2026-78047
No vendor fix or workaround currently provided.
OpenCVE Recommended Actions
- Upgrade WatchGuard Dimension to version 2.3.1 or later to remove the stored‑XSS flaw.
- Limit the use of the Backup Historical Data feature to a small group of trusted administrative accounts and enforce least‑privilege access controls.
- If a patch cannot be applied immediately, consider disabling the feature or removing existing historical data entries to eliminate the stored script source while monitoring usage log events for suspicious activity.
Generated by OpenCVE AI on August 28, 2026 at 07:48 UTC.
Tracking
Sign in to view the affected projects.
No advisories yet.
No reference.
Thu, 03 Sep 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Fri, 28 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Cross-Site Scripting (XSS) vulnerability in the WatchGuard Dimension Backup Historical Data feature allows an authenticated administrator user to execute arbitrary JavaScript in another user's browser. | Rejecting as a duplicate of CVE-2026-78047 |
| Title | Dimension Stored XSS via Backup Historical Data Feature | |
| CPEs | ||
| Metrics |
cvssV4_0
|
cvssV4_0
|
Thu, 27 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Cross-Site Scripting (XSS) vulnerability in the WatchGuard Dimension Backup Historical Data feature allows an authenticated administrator user to execute arbitrary JavaScript in another user's browser. | |
| Title | Dimension Stored XSS via Backup Historical Data Feature | |
| First Time appeared |
Watchguard
Watchguard dimension |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:watchguard:dimension:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Watchguard
Watchguard dimension |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: REJECTED
Assigner: WatchGuard
Published:
Updated: 2026-08-28T14:33:35.260Z
Reserved: 2026-08-23T20:50:31.029Z
Link: CVE-2026-78195
No data.
Status : Rejected
Published: 2026-08-28T02:16:23.080
Modified: 2026-09-03T05:13:07.860
Link: CVE-2026-78195
No data.
OpenCVE Enrichment
Updated: 2026-08-28T08:00:13Z
No weakness.