ZeroHour

CVE-2026-78612

moderate

Authenticated SQL Injection Leading to RCE in WatchGuard Dimension

CVSS 4.0
8.6 high
EPSS
<1%p52
Published
()
Modified
AI analysis

WatchGuard Dimension contains an authenticated SQL injection vulnerability (CWE-89; the CWE mapping also includes CWE-502, deserialization of untrusted data) in its scheduled report feature. An attacker who holds an account with report administration permissions can trigger the flaw by sending specially crafted requests to that feature. Successful exploitation yields arbitrary command execution as the user running the Dimension WebUI process, and the flaw carries a CVSS 4.0 score of 8.6 (high). Only organizations running WatchGuard Dimension are affected; the available data does not specify which version ranges are impacted. There is no known public proof-of-concept, the issue is not in CISA KEV, and EPSS assigns a 0.7% probability of exploitation within 30 days, so no active exploitation is confirmed at this time.

What to do: Upgrade WatchGuard Dimension to the fixed release identified in WatchGuard's advisory for CVE-2026-78612 (the available data does not state a specific version number). Until patched, limit Dimension WebUI access to trusted networks, minimize the number of accounts with report administration permissions, and review logs for unusual requests to the scheduled report feature.

Affected
WatchGuard Dimension
Estimated exposure
moderateon the order of 10k-100k Dimension deployments (estimate; no public install-base figure in the data) — Dimension is an optional reporting/visibility appliance deployed at a subset of WatchGuard Firebox customers, whose installed base is commonly cited in the hundreds of thousands, with larger sites and MSPs being the most likely Dimension…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

WatchGuard Dimension contains an authenticated SQL injection vulnerability in the scheduled report feature which allows an authenticated user with report administration permissions gain arbitrary command execution as the Dimension WebUI process user by sending specially crafted requests.

Weakness
CWE-89, CWE-502
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.