CVE-2026-78612
moderateAuthenticated SQL Injection Leading to RCE in WatchGuard Dimension
WatchGuard Dimension contains an authenticated SQL injection vulnerability (CWE-89; the CWE mapping also includes CWE-502, deserialization of untrusted data) in its scheduled report feature. An attacker who holds an account with report administration permissions can trigger the flaw by sending specially crafted requests to that feature. Successful exploitation yields arbitrary command execution as the user running the Dimension WebUI process, and the flaw carries a CVSS 4.0 score of 8.6 (high). Only organizations running WatchGuard Dimension are affected; the available data does not specify which version ranges are impacted. There is no known public proof-of-concept, the issue is not in CISA KEV, and EPSS assigns a 0.7% probability of exploitation within 30 days, so no active exploitation is confirmed at this time.
What to do: Upgrade WatchGuard Dimension to the fixed release identified in WatchGuard's advisory for CVE-2026-78612 (the available data does not state a specific version number). Until patched, limit Dimension WebUI access to trusted networks, minimize the number of accounts with report administration permissions, and review logs for unusual requests to the scheduled report feature.
| WatchGuard Dimension | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
WatchGuard Dimension contains an authenticated SQL injection vulnerability in the scheduled report feature which allows an authenticated user with report administration permissions gain arbitrary command execution as the Dimension WebUI process user by sending specially crafted requests.
- Weakness
- CWE-89, CWE-502
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.