Description
WatchGuard Dimension contains an authenticated SQL injection vulnerability in the log viewer feature which allows an authenticated user with report administration permissions gain arbitrary command execution as the Dimension WebUI process user by sending specially crafted requests.
Published: 2026-08-27
Score: 8.6 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

WatchGuard Dimension contains an authenticated SQL injection in the log viewer feature. When an attacker with report administration privileges sends a crafted request, the vulnerability allows execution of arbitrary commands as the Dimension WebUI process user.

Affected Systems

All versions of WatchGuard Dimension prior to the 2.3.1 release are affected. The CVE specifically references the Dimension product from WatchGuard.

Risk and Exploitability

Based on the description, it is inferred that the attacker must be an authenticated user with report administration permissions, and the exploitation involves sending specially crafted requests to the log viewer endpoint. The vulnerability has a CVSS score of 8.6, indicating high severity. The EPSS score is not available, and it is not listed in the CISA KEV catalog. Exploitation requires legitimate authentication with report administration permissions, so it is an insider or credential-compromise threat rather than remote exploitation. The impact includes full system compromise through command execution as the Dimension WebUI process user.

Generated by OpenCVE AI on August 28, 2026 at 08:12 UTC.

Remediation

Vendor Solution

Dimension 2.3.1


OpenCVE Recommended Actions

  • Upgrade to WatchGuard Dimension 2.3.1
  • Restrict report administration privileges to trusted users only
  • Disallow or monitor the log viewer feature for anomalous activity

Generated by OpenCVE AI on August 28, 2026 at 08:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description WatchGuard Dimension contains an authenticated SQL injection vulnerability in the log viewer feature which allows an authenticated user with report administration permissions gain arbitrary command execution as the Dimension WebUI process user by sending specially crafted requests.
Title Dimension SQL Injection in Log Viewer
First Time appeared Watchguard
Watchguard dimension
Weaknesses CWE-89
CPEs cpe:2.3:a:watchguard:dimension:*:*:*:*:*:*:*:*
Vendors & Products Watchguard
Watchguard dimension
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Watchguard Dimension
cve-icon MITRE

Status: PUBLISHED

Assigner: WatchGuard

Published:

Updated: 2026-08-27T23:26:31.266Z

Reserved: 2026-08-24T21:18:31.631Z

Link: CVE-2026-78613

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-28T02:16:23.943

Modified: 2026-08-28T02:16:23.943

Link: CVE-2026-78613

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T08:15:06Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')