CVE-2026-78614

8.6

WatchGuard · Dimension

WatchGuard Dimension is vulnerable to an authenticated SQL injection in the audit report feature, allowing an attacker with report administration permissions to achieve arbitrary command execution.

Executive summary

WatchGuard Dimension contains an authenticated SQL injection vulnerability that allows an attacker with administrative privileges to execute arbitrary commands on the affected system.

Vulnerability

This vulnerability is a SQL injection flaw located in the audit report feature. It requires the attacker to hold report administration permissions to trigger the injection, which ultimately facilitates arbitrary command execution under the context of the Dimension WebUI process user.

Business impact

The ability to execute arbitrary commands on a network security management appliance presents a severe risk to the entire security infrastructure. An attacker could leverage this access to compromise sensitive log data, escalate privileges, or pivot deeper into the internal network. With a CVSS score of 8.6, this high severity vulnerability necessitates immediate attention to prevent full system compromise.

Remediation

Immediate Action: Upgrade WatchGuard Dimension to version 2.3.1 or later to apply the vendor-supplied security patch.

Proactive Monitoring: Review system logs for anomalous activity related to the audit report module and monitor for unexpected process execution originating from the web interface.

Compensating Controls: Restrict access to the Dimension WebUI to trusted administrative internal networks and verify that the principle of least privilege is applied to all user accounts with report administration rights.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the potential for remote command execution, organizations must prioritize updating their WatchGuard Dimension instances to version 2.3.1 immediately. Ensure that administrative access is strictly controlled and audited to mitigate the risk of an attacker leveraging compromised credentials to exploit this flaw. Failure to patch allows for significant risk of lateral movement and persistent access within the management environment.

More WatchGuard CVEs

Sources

Originally found and disclosed by Yukusawa18, per the CVE Program record.