CVE-2026-78612
Deferred Deferred - Pending Action

Authenticated SQL Injection in WatchGuard Dimension Leading to Command Execution

Vulnerability report for CVE-2026-78612, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-28

Last updated on: 2026-08-28

Assigner: WatchGuard Technologies, Inc.

Description

WatchGuard Dimension contains an authenticated SQL injection vulnerability in the scheduled report feature which allows an authenticated user with report administration permissions gain arbitrary command execution as the Dimension WebUI process user by sending specially crafted requests.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-28
Last Modified
2026-08-28
Generated
2026-09-17
AI Q&A
2026-08-28
EPSS Evaluated
2026-09-15
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
watchguard dimension to 2.3.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-89 The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CWE-502 The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

WatchGuard Dimension has an authenticated SQL injection flaw in its scheduled report feature. An attacker with report admin rights or tricked via CSRF can run stacked SQL commands against the database. This can lead to writing a malicious session file, which when triggered via a session cookie, allows remote code execution as the WebUI process user (wgadmin).

Detection Guidance

Detecting this vulnerability requires checking WatchGuard Dimension versions prior to 2.3.1. Verify the installed version via the admin interface or command line. Look for unauthorized scheduled reports or suspicious SQL queries in logs. No specific commands are provided in the resources.

Impact Analysis

Exploitation enables full compromise of the WebUI process, allowing session tampering, file read/write, modification of reporting data, and potential access to connected logging and Firebox management workflows. This could lead to unauthorized data access or system control.

Compliance Impact

This vulnerability could lead to unauthorized data access or modification, potentially violating GDPR (data protection) and HIPAA (health data privacy) by exposing sensitive information or altering records.

Mitigation Strategies

Upgrade WatchGuard Dimension to version 2.3.1 or later immediately. Remove unnecessary report administration privileges. Monitor for unusual activity in the WebUI process or session files. Apply patches as soon as they are available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78612. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart