Junglewise Threat Intelligence

CVE-2026-78047: WatchGuard Dimension stored XSS in task scheduling

CVE-2026-78047 · Severity: info · CVSS 5.1 · Published 2026-08-28

Technologies: Watchguard Dimension. Vendors: Watchguard.

Executive brief

WatchGuard Dimension is a reporting and analytics platform used by organizations to monitor security events and generate reports. A stored cross-site scripting vulnerability in the task scheduling feature allows a low-privileged authenticated administrator to inject malicious scripts that execute when other users view scheduled reports, potentially enabling account takeover or unauthorized data access.

Technical details

This is a stored cross-site scripting (CWE-79) vulnerability in WatchGuard Dimension's task scheduling feature. A low-privileged authenticated administrator can inject arbitrary HTML and JavaScript into task scheduling fields; the injected payload is stored and later executed in the browser context of any other user who accesses or views the scheduled report. The attack requires valid administrative credentials and user interaction (viewing the report). The vulnerability affects Dimension versions 2.0 through 2.3.0; a patch is available in version 2.3.1.

Affected products

  • WatchGuard Dimension 2.0 through 2.3.0

Timeline

  • 2026-08-27: disclosed
  • 2026-08-27: patched: Fixed in Dimension 2.3.1

References

Related threats