WatchGuard TechnologiesCVE-2026-78613
WatchGuard Technologies Dimension: SQL injection
High8.6CVE-2026-78613 · Published Aug 28, 2026
WatchGuard Dimension contains an authenticated SQL injection vulnerability in the log viewer feature which allows an authenticated user with report administration permissions gain arbitrary command execution as the Dimension WebUI process user by sending specially crafted requests.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Dimension Product | >= 2.0, < 2.3.1 | 2.3.1 |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-89
More WatchGuard Technologies advisories
All WatchGuard Technologies| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 28 | WatchGuard Technologies Dimension: SQL injection | High8.6 | 2.3.1 |
| Aug 28 | WatchGuard Technologies Dimension: cross-site scripting | Medium4.6 | 2.3.1 |
| Aug 28 | WatchGuard Technologies Dimension: cross-site scripting | Medium4.8 | 2.3.1 |
| Aug 28 | WatchGuard Technologies Dimension: observable discrepancy | Medium6.3 | 2.3.1 |
| Aug 28 | WatchGuard Technologies Dimension: improper access control | Medium6.9 | 2.3.1 |
| Aug 28 | WatchGuard Technologies Dimension: server-side request forgery | Medium5.3 | 2.3.1 |