ZeroHour

CVE-2026-78613

moderate

Authenticated SQL Injection (RCE) in WatchGuard Dimension Log Viewer

CVSS 4.0
8.6 high
EPSS
<1%p48
Published
()
Modified
AI analysis

WatchGuard Dimension, the on-premises logging and reporting appliance used with WatchGuard Firebox/XTM firewalls, contains a SQL injection flaw (CWE-89) in its log viewer feature. An authenticated user holding report administration permissions can send specially crafted requests to the log viewer, and the injected query can be leveraged to execute arbitrary operating-system commands as the Dimension WebUI process user. Successful exploitation yields full command execution on the Dimension appliance at the privilege of its web process, though it requires valid, highly privileged credentials and the CVSS 4.0 scope-unchanged baseline indicates impact is contained to the Dimension system itself rather than the firewalls it monitors. Any organization running WatchGuard Dimension is affected; the source data does not specify affected or fixed versions. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, and EPSS assigns a 0.6% probability of exploitation within 30 days (48th percentile).

What to do: Upgrade Dimension to the patched release identified in WatchGuard's security advisory; the source data does not name a fixed version, so verify against the vendor portal. Until patched, restrict network access to the Dimension WebUI and limit report administrator accounts to trusted management hosts. Review log-viewer access logs for anomalous crafted requests and check for unexpected processes spawned by the Dimension WebUI service account.

Affected
WatchGuard Dimension (log viewer feature)
Estimated exposure
moderatelikely on the order of 10,000-30,000 on-premises Dimension deployments worldwide, of which only a few thousand are exposed to the public internet — Dimension is an optional on-premises reporting appliance deployed by a subset of WatchGuard's large Firebox/XTM customer base (many estates have moved to WatchGuard Cloud), and public internet scans historically show only a few thousand…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

WatchGuard Dimension contains an authenticated SQL injection vulnerability in the log viewer feature which allows an authenticated user with report administration permissions gain arbitrary command execution as the Dimension WebUI process user by sending specially crafted requests.

Weakness
CWE-89
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.