Executive brief
WatchGuard Dimension is a reporting and analytics platform used by organizations to monitor security events and generate reports. A stored cross-site scripting vulnerability in the task scheduling feature allows a low-privileged authenticated administrator to inject malicious scripts that execute when other users view scheduled reports, potentially enabling account takeover or unauthorized data access.
Technical details
This is a stored cross-site scripting (CWE-79) vulnerability in WatchGuard Dimension's task scheduling feature. A low-privileged authenticated administrator can inject arbitrary HTML and JavaScript into task scheduling fields; the injected payload is stored and later executed in the browser context of any other user who accesses or views the scheduled report. The attack requires valid administrative credentials and user interaction (viewing the report). The vulnerability affects Dimension versions 2.0 through 2.3.0; a patch is available in version 2.3.1.
Affected products
- WatchGuard Dimension 2.0 through 2.3.0
Timeline
- 2026-08-27: disclosed
- 2026-08-27: patched: Fixed in Dimension 2.3.1