CVE-2026-78613

8.6

WatchGuard · Dimension

WatchGuard Dimension is vulnerable to an authenticated SQL injection in the log viewer, allowing an attacker with administrative permissions to execute arbitrary commands as the WebUI process user.

Executive summary

An authenticated SQL injection vulnerability in WatchGuard Dimension allows attackers with administrative privileges to achieve remote code execution, posing a high risk to system integrity.

Vulnerability

The flaw is a SQL injection (CWE-89) triggered within the log viewer feature. It requires an attacker to possess report administration permissions to submit malicious requests that lead to arbitrary command execution.

Business impact

Successful exploitation allows an attacker to execute commands with the privileges of the Dimension WebUI process, potentially leading to full system compromise. Given the CVSS score of 8.6, this vulnerability represents a high risk: it could allow unauthorized access to sensitive log data or provide a foothold for further lateral movement within the network.

Remediation

Immediate Action: Update WatchGuard Dimension to version 2.3.1 or later to resolve the underlying SQL injection flaw.

Proactive Monitoring: Review system logs for unusual queries directed at the log viewer feature and monitor for unexpected process execution originating from the WebUI user account.

Compensating Controls: Restrict access to the administrative console to trusted internal IP addresses and employ a Web Application Firewall to filter malicious SQL syntax from incoming web requests.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability presents a significant risk due to the potential for remote code execution. Administrators should prioritize upgrading to version 2.3.1 immediately to eliminate the injection vector and secure the administrative interface against unauthorized command execution.

More WatchGuard CVEs

Sources

Originally found and disclosed by Yukusawa18, per the CVE Program record.