Junglewise Threat Intelligence

CVE-2026-78614: WatchGuard Dimension SQL injection in audit report feature

CVE-2026-78614 · Severity: info · CVSS 8.6 · Published 2026-08-28

Technologies: Watchguard Dimension. Vendors: Watchguard.

Executive brief

WatchGuard Dimension is a network monitoring and management platform used to oversee security appliances and network operations. An authenticated user with report administration permissions can exploit a SQL injection vulnerability in the audit report feature to execute arbitrary commands on the Dimension server, potentially compromising the entire monitoring infrastructure and gaining access to sensitive network data.

Technical details

The vulnerability is an authenticated SQL injection (CWE-89) in WatchGuard Dimension's audit report feature, combined with deserialization of untrusted data (CWE-502). An authenticated user with report administration permissions can craft specially formed requests to inject malicious SQL commands into audit report queries. The attack requires valid credentials and the specific admin role, but allows arbitrary command execution with the privileges of the Dimension WebUI process. The vulnerability affects versions 2.0 through 2.3.0; version 2.3.1 and later contain the fix.

Affected products

  • WatchGuard Dimension 2.0 through 2.3.0

Timeline

  • 2026-08-27: disclosed
  • 2026-08-27: patched: Dimension 2.3.1 released

References

Related threats