CVE-2026-78613
moderateAuthenticated SQL Injection (RCE) in WatchGuard Dimension Log Viewer
WatchGuard Dimension, the on-premises logging and reporting appliance used with WatchGuard Firebox/XTM firewalls, contains a SQL injection flaw (CWE-89) in its log viewer feature. An authenticated user holding report administration permissions can send specially crafted requests to the log viewer, and the injected query can be leveraged to execute arbitrary operating-system commands as the Dimension WebUI process user. Successful exploitation yields full command execution on the Dimension appliance at the privilege of its web process, though it requires valid, highly privileged credentials and the CVSS 4.0 scope-unchanged baseline indicates impact is contained to the Dimension system itself rather than the firewalls it monitors. Any organization running WatchGuard Dimension is affected; the source data does not specify affected or fixed versions. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, and EPSS assigns a 0.6% probability of exploitation within 30 days (48th percentile).
What to do: Upgrade Dimension to the patched release identified in WatchGuard's security advisory; the source data does not name a fixed version, so verify against the vendor portal. Until patched, restrict network access to the Dimension WebUI and limit report administrator accounts to trusted management hosts. Review log-viewer access logs for anomalous crafted requests and check for unexpected processes spawned by the Dimension WebUI service account.
| WatchGuard Dimension (log viewer feature) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
WatchGuard Dimension contains an authenticated SQL injection vulnerability in the log viewer feature which allows an authenticated user with report administration permissions gain arbitrary command execution as the Dimension WebUI process user by sending specially crafted requests.
- Weakness
- CWE-89
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.