Junglewise Threat Intelligence

CVE-2026-78616: WatchGuard Dimension stored XSS in Trusted CA certificate configuration

CVE-2026-78616 · Severity: info · CVSS 4.8 · Published 2026-08-28

Technologies: Watchguard Dimension. Vendors: Watchguard.

Executive brief

WatchGuard Dimension is a security management and reporting platform used by administrators to monitor and control network security devices. A stored cross-site scripting vulnerability in the Trusted CA certificate configuration allows an authenticated administrator to inject malicious code that executes in the browser of other administrators, potentially leading to unauthorized actions, credential theft, or system compromise.

Technical details

A Stored Cross-Site Scripting (CWE-79) vulnerability exists in WatchGuard Dimension's Trusted CA certificate configuration feature. An authenticated administrator can upload or save a specially crafted certificate containing malicious JavaScript that is not properly sanitized. When another authenticated administrator accesses the certificate configuration, the stored payload is executed in their browser context, allowing the attacker to perform administrative actions, steal session tokens, or modify system settings. The vulnerability requires authentication and user interaction (visiting the affected configuration page). WatchGuard released patch version 2.3.1 to address this issue.

Affected products

  • WatchGuard Dimension 2.0 to 2.3.0

Timeline

  • 2026-08-27: disclosed
  • 2026-08-27: patched: Version 2.3.1 released

References

Related threats