CVE-2026-78614
moderateAuthenticated SQL Injection to RCE in WatchGuard Dimension
WatchGuard Dimension, the vendor's on-premises network visibility and log-management appliance, contains an authenticated SQL injection flaw (CWE-89) in its audit report feature. An authenticated user holding report administration permissions can send specially crafted requests to that feature, and the injected input leads to arbitrary command execution as the Dimension WebUI process user; the associated CWE-502 (deserialization of untrusted data) mapping suggests the injection may flow into a deserialization step to achieve command execution. Because CVSS 4.0 rates high impact to confidentiality, integrity, and availability of the vulnerable component, attackers gaining command execution can compromise the appliance and any data it manages, though privileges are limited to the WebUI service account. Only organizations running WatchGuard Dimension, typically deployed alongside WatchGuard Firebox firewalls for centralized logging and reporting, are affected. There are no known reports of in-the-wild exploitation, no public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns a modest 0.7% probability of exploitation within 30 days.
What to do: Upgrade WatchGuard Dimension to the latest patched release published by the vendor (the specific fixed version is not stated in the available data — check the WatchGuard advisory). Until patched, restrict access to the Dimension WebUI to trusted management networks, minimize the number of accounts holding report administration rights, and review Dimension audit/reporting logs for anomalous or crafted report requests.
| WatchGuard Dimension | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
WatchGuard Dimension contains an authenticated SQL injection vulnerability in the audit report feature which allows an authenticated user with report administration permissions gain arbitrary command execution as the Dimension WebUI process user by sending specially crafted requests.
- Weakness
- CWE-89, CWE-502
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.