Junglewise Threat Intelligence

CVE-2026-78612: WatchGuard Dimension SQL injection in scheduled report feature

CVE-2026-78612 · Severity: info · CVSS 8.6 · Published 2026-08-28

Technologies: Watchguard Dimension. Vendors: Watchguard.

Executive brief

WatchGuard Dimension is a security monitoring and reporting platform used by organizations to track network activity and generate compliance reports. The scheduled report feature contains a SQL injection vulnerability that allows authenticated users with report administration permissions to execute arbitrary commands on the underlying server, potentially compromising system integrity and enabling lateral movement within the network.

Technical details

This is a SQL injection vulnerability (CWE-89) in the scheduled report feature of WatchGuard Dimension, exploitable only by authenticated users possessing report administration permissions. The vulnerability allows attackers to craft specially crafted requests that inject SQL commands, leading to arbitrary command execution with the privileges of the Dimension WebUI process. Attack preconditions include valid authentication credentials and the specific administrative role; the attack vector is network-based via the WebUI. WatchGuard has released Dimension 2.3.1 as a patch addressing this vulnerability.

Affected products

  • WatchGuard Dimension 2.0 to 2.3.0

Timeline

  • 2026-08-27: disclosed
  • 2026-08-27: patched: Dimension 2.3.1 released

References

Related threats