Description
WatchGuard Dimension contains an authenticated SQL injection vulnerability in the audit report feature which allows an authenticated user with report administration permissions gain arbitrary command execution as the Dimension WebUI process user by sending specially crafted requests.
Published: 2026-08-27
Score: 8.6 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

WatchGuard Dimension includes an authenticated SQL injection flaw in its audit report component. A user who has report administration permissions can craft requests that inject SQL, enabling the execution of arbitrary system commands under the privileges of the Dimension WebUI process. This leads to privilege escalation on the host and can compromise the entire network segment running the appliance.

Affected Systems

The vulnerability affects the WatchGuard Dimension product. No specific sub‑versions are listed as affected, but the official fix is available in Dimension 2.3.1, implying that earlier releases lack the patch.

Risk and Exploitability

The CVSS score of 8.6 indicates a high impact potential. Exploitation requires valid authentication and appropriate permissions, limiting it to users with report admin rights. While an EPSS score is not supplied, the lack of a KEV listing suggests a lower current exploitation rate; however, the possibility of internal exploitation remains high, warranting urgent remediation.

Generated by OpenCVE AI on August 28, 2026 at 07:33 UTC.

Remediation

Vendor Solution

Dimension 2.3.1


OpenCVE Recommended Actions

  • Upgrade Dimension to version 2.3.1 or later
  • Revoke report administration privileges from users who do not require them
  • Monitor audit request logs for abnormal or unauthorized activity

Generated by OpenCVE AI on August 28, 2026 at 07:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description WatchGuard Dimension contains an authenticated SQL injection vulnerability in the audit report feature which allows an authenticated user with report administration permissions gain arbitrary command execution as the Dimension WebUI process user by sending specially crafted requests.
Title Dimension SQL Injection in Audit Report
First Time appeared Watchguard
Watchguard dimension
Weaknesses CWE-502
CWE-89
CPEs cpe:2.3:a:watchguard:dimension:*:*:*:*:*:*:*:*
Vendors & Products Watchguard
Watchguard dimension
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Watchguard Dimension
cve-icon MITRE

Status: PUBLISHED

Assigner: WatchGuard

Published:

Updated: 2026-08-27T23:26:30.524Z

Reserved: 2026-08-24T21:18:36.818Z

Link: CVE-2026-78614

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-28T02:16:24.070

Modified: 2026-08-28T02:16:24.070

Link: CVE-2026-78614

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T07:45:04Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')