CVE-2026-78612

8.6

WatchGuard · Dimension

WatchGuard Dimension contains an authenticated SQL injection vulnerability in the scheduled report feature that allows users with report administration permissions to achieve arbitrary command execution.

Executive summary

WatchGuard Dimension is vulnerable to an authenticated SQL injection flaw that enables remote command execution, posing a high risk to system integrity.

Vulnerability

The vulnerability exists within the scheduled report feature, where improper handling of input allows an authenticated user with report administration privileges to perform SQL injection. This flaw can be leveraged to execute arbitrary commands as the Dimension WebUI process user.

Business impact

Successful exploitation of this vulnerability allows an attacker with existing administrative access to escalate their control to the underlying operating system. This could lead to a full compromise of the Dimension server, resulting in unauthorized data access, potential lateral movement within the network, and significant disruption to security monitoring operations. The CVSS score of 8.6 reflects the high severity of achieving command execution within a security management appliance.

Remediation

Immediate Action: Update WatchGuard Dimension to version 2.3.1 or later to resolve the underlying vulnerability.

Proactive Monitoring: Review system and application logs for anomalous database queries or unexpected process execution patterns originating from the WebUI process user.

Compensating Controls: Restrict administrative access to the Dimension WebUI to trusted internal management subnets and enforce strict least-privilege policies for all user accounts.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the potential for complete system compromise, organizations should prioritize upgrading their WatchGuard Dimension instances to version 2.3.1 immediately. Until the patch is applied, ensure that administrative access is restricted to verified personnel to minimize the likelihood of exploitation.

More WatchGuard CVEs

Sources

Originally found and disclosed by Yukusawa18, per the CVE Program record.