Description
A Cross-Site Request Forgery (CSRF) vulnerability in WatchGuard Dimension's database snapshot creation feature allows a remote attacker to trigger unauthorized snapshot creation by tricking an authenticated administrator into visiting a specially crafted web page.
Published: 2026-09-08
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

The vulnerability is a Cross‑Site Request Forgery that permits a remote attacker to coerce an authenticated administrator into creating a database snapshot. When triggered, the snapshot consumes significant disk space and I/O, potentially exhausting system resources and causing a service interruption. The lack of proper resource limits also contributes to a denial‑of‑service outcome while the database remains otherwise operational.

Affected Systems

The flaw exists in WatchGuard Dimension, all builds prior to 2.3.1. Administrators with access to the web console for snapshot creation are the primary risk group, and the vulnerability is confined to the snapshot creation endpoint.

Risk and Exploitability

The CVSS score of 7 indicates a high threat level. Exploitation requires an authenticated admin session and user interaction, so the EPSS score is unavailable but targeted attacks are viable. The feature is not listed in the CISA KEV catalog, suggesting no known active exploits yet, yet attackers can craft a malicious link that will be executed by an unwary admin, leading to a resource‑heavy snapshot and eventual denial of service.

Generated by OpenCVE AI on September 8, 2026 at 16:10 UTC.

Remediation

Vendor Solution

Dimension 2.3.1


OpenCVE Recommended Actions

  • Update Dimension to version 2.3.1 or later, which removes the exploitable snapshot endpoint.
  • If patch cannot be applied immediately, restrict snapshot creation by disabling the feature or limiting it to a small set of trusted administrators.
  • Enforce CSRF protection by requiring a server‑generated token or blocking snapshot requests that lack a valid CSRF token.

Generated by OpenCVE AI on September 8, 2026 at 16:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description A Cross-Site Request Forgery (CSRF) vulnerability in WatchGuard Dimension's database snapshot creation feature allows a remote attacker to trigger unauthorized snapshot creation by tricking an authenticated administrator into visiting a specially crafted web page.
Title Dimension CSRF Vulnerability in Database Snapshot Creation Allows Denial of Service
First Time appeared Watchguard
Watchguard dimension
Weaknesses CWE-352
CWE-400
CPEs cpe:2.3:a:watchguard:dimension:*:*:*:*:*:*:*:*
Vendors & Products Watchguard
Watchguard dimension
References
Metrics cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Watchguard Dimension
cve-icon MITRE

Status: PUBLISHED

Assigner: WatchGuard

Published:

Updated: 2026-09-08T14:37:57.032Z

Reserved: 2026-09-05T03:13:15.861Z

Link: CVE-2026-86135

cve-icon Vulnrichment

Updated: 2026-09-08T14:37:53.675Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T15:18:52.650

Modified: 2026-09-08T19:15:18.627

Link: CVE-2026-86135

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T16:15:15Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)

  • CWE-400

    Uncontrolled Resource Consumption