CVE-2026-78047: Dimension Stored XSS in Scheduled Report Task
Published Aug 27, 2026
·Updated
A stored cross-site scripting (XSS) vulnerability in WatchGuard Dimension's task scheduling feature allows a low-privileged authenticated administrator to inject arbitrary HTML/JavaScript into these fields, which then executes in the browser session of any other user.
Affected Software
1 affected component
WatchGuard WatchGuard Dimension
Event History
Aug 27, 2026
CVE Published
via MITRE·11:26 PM
Data Sourced
via MITRE·11:26 PM
RemedyDescriptionWeakness
Aug 28, 2026
Data Sourced
via NVD·02:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker must have an authenticated, low-privileged administrator account with access to the task scheduling feature.
2
Which users are at risk from a malicious scheduled task?
Any user who views the affected content in their browser can have the injected HTML or JavaScript execute in that browser session.