CVE-2026-78612: Dimension SQL Injection in Scheduled Report
Published Aug 27, 2026
·Updated
WatchGuard Dimension contains an authenticated SQL injection vulnerability in the scheduled report feature which allows an authenticated user with report administration permissions gain arbitrary command execution as the Dimension WebUI process user by sending specially crafted requests.
Affected Software
1 affected component
WatchGuard WatchGuard Dimension
Event History
Aug 27, 2026
CVE Published
via MITRE·11:26 PM
Data Sourced
via MITRE·11:26 PM
RemedyDescriptionWeakness
Frequently Asked Questions
1
Which accounts should be treated as capable of exploiting this issue?
Any authenticated account with report administration permissions can exploit the vulnerability through specially crafted requests to the scheduled report feature. Successful exploitation can result in command execution as the Dimension WebUI process user.