Junglewise Threat Intelligence

CVE-2026-78613: WatchGuard Dimension SQL injection in log viewer

CVE-2026-78613 · Severity: info · CVSS 8.6 · Published 2026-08-28

Technologies: Watchguard Dimension. Vendors: Watchguard.

Executive brief

WatchGuard Dimension is a security monitoring and reporting platform used to analyze logs and security events. An authenticated SQL injection vulnerability in the log viewer allows users with report administration permissions to execute arbitrary commands on the system, potentially leading to full compromise of the monitoring infrastructure and unauthorized access to sensitive security data.

Technical details

The vulnerability is an authenticated SQL injection (CWE-89) in the log viewer component of WatchGuard Dimension. An attacker must be authenticated with report administration permissions to exploit this flaw. By sending specially crafted requests containing malicious SQL syntax, an attacker can break out of the intended SQL query and execute arbitrary commands as the Dimension WebUI process user. The vulnerability has been patched in version 2.3.1, and WatchGuard has not observed any exploitation in the wild as of the advisory publication date.

Affected products

  • WatchGuard Dimension before 2.3.1

Timeline

  • 2026-08-27: disclosed
  • 2026-08-27: patched: Fixed in version 2.3.1

References

Related threats