CVE-2026-78614
8.6WatchGuard · Dimension
WatchGuard Dimension is vulnerable to an authenticated SQL injection in the audit report feature, allowing an attacker with report administration permissions to achieve arbitrary command execution.
Executive summary
WatchGuard Dimension contains an authenticated SQL injection vulnerability that allows an attacker with administrative privileges to execute arbitrary commands on the affected system.
Vulnerability
This vulnerability is a SQL injection flaw located in the audit report feature. It requires the attacker to hold report administration permissions to trigger the injection, which ultimately facilitates arbitrary command execution under the context of the Dimension WebUI process user.
Business impact
The ability to execute arbitrary commands on a network security management appliance presents a severe risk to the entire security infrastructure. An attacker could leverage this access to compromise sensitive log data, escalate privileges, or pivot deeper into the internal network. With a CVSS score of 8.6, this high severity vulnerability necessitates immediate attention to prevent full system compromise.
Remediation
Immediate Action: Upgrade WatchGuard Dimension to version 2.3.1 or later to apply the vendor-supplied security patch.
Proactive Monitoring: Review system logs for anomalous activity related to the audit report module and monitor for unexpected process execution originating from the web interface.
Compensating Controls: Restrict access to the Dimension WebUI to trusted administrative internal networks and verify that the principle of least privilege is applied to all user accounts with report administration rights.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the potential for remote command execution, organizations must prioritize updating their WatchGuard Dimension instances to version 2.3.1 immediately. Ensure that administrative access is strictly controlled and audited to mitigate the risk of an attacker leveraging compromised credentials to exploit this flaw. Failure to patch allows for significant risk of lateral movement and persistent access within the management environment.
More WatchGuard CVEs
Sources
Originally found and disclosed by Yukusawa18, per the CVE Program record.