Junglewise Threat Intelligence

CVE-2026-78615: WatchGuard Dimension reflected XSS in report detail page

CVE-2026-78615 · Severity: info · CVSS 4.6 · Published 2026-08-28

Technologies: Watchguard Dimension. Vendors: Watchguard.

Executive brief

WatchGuard Dimension is a network monitoring and analytics platform used by enterprises to manage security data. A reflected cross-site scripting vulnerability in the report detail page allows an attacker to trick authenticated users into clicking a malicious link, which would execute arbitrary JavaScript in their browser and potentially steal sensitive data or perform unauthorized actions on their behalf.

Technical details

This is a reflected DOM-based cross-site scripting (XSS) vulnerability (CWE-79) in WatchGuard Dimension's report detail page. The vulnerability allows an attacker to craft a malicious URL that, when clicked by an authenticated user, injects and executes arbitrary JavaScript in the victim's browser context. Exploitation requires user interaction (clicking a link) and an authenticated session. An attacker can use this to steal session tokens, perform actions as the authenticated user, or exfiltrate sensitive security data. The vulnerability affects Dimension versions 2.0 through 2.3.0; WatchGuard released a patch in version 2.3.1.

Affected products

  • WatchGuard Dimension 2.0 through 2.3.0

Timeline

  • 2026-08-27: disclosed
  • 2026-08-27: patched: Fixed in version 2.3.1

References

Related threats