CVE-2026-86135
moderateCSRF in WatchGuard Dimension Allows Forced Database Snapshot Creation
WatchGuard Dimension, the vendor's centralized log-management and reporting product for Firebox deployments, contains a cross-site request forgery (CSRF) flaw in its database snapshot creation feature (CWE-352, CWE-400). An attacker triggers it by luring an authenticated Dimension administrator into visiting a crafted web page, causing the browser to silently issue an unauthorized snapshot-creation request. The attacker gains no confidentiality impact and only limited integrity impact, but the CVSS 4.0 vector (VA:H) and CWE-400 indicate repeated or oversized forced snapshots can cause high-availability impact through disk and resource exhaustion on the appliance. Any organization running Dimension whose administrators browse the web with authenticated sessions open is potentially affected. There is no known public proof of concept, it is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at just 0.2%.
What to do: Update WatchGuard Dimension to the patched release identified in the vendor's security advisory (specific fixed versions are not stated in the available data). Until patching, restrict the Dimension management interface to trusted networks, log out of admin sessions promptly, and avoid browsing untrusted sites from the same browser session. Because the impact is availability-oriented (CWE-400), also monitor appliance disk usage and review recent snapshot activity for anomalies.
| WatchGuard Dimension | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A Cross-Site Request Forgery (CSRF) vulnerability in WatchGuard Dimension's database snapshot creation feature allows a remote attacker to trigger unauthorized snapshot creation by tricking an authenticated administrator into visiting a specially crafted web page.
- Weakness
- CWE-352, CWE-400
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.