CVE-2026-78613: Dimension SQL Injection in Log Viewer
Published Aug 27, 2026
·Updated
WatchGuard Dimension contains an authenticated SQL injection vulnerability in the log viewer feature which allows an authenticated user with report administration permissions gain arbitrary command execution as the Dimension WebUI process user by sending specially crafted requests.
Affected Software
1 affected component
WatchGuard WatchGuard Dimension
Event History
Aug 27, 2026
CVE Published
via MITRE·11:26 PM
Data Sourced
via MITRE·11:26 PM
RemedyDescriptionWeakness
Frequently Asked Questions
1
Which accounts are able to exploit this issue?
An attacker must authenticate to WatchGuard Dimension and have report administration permissions. The issue is not described as exploitable by unauthenticated users or by accounts without those permissions.
2
What level of access can successful exploitation provide?
Successful exploitation can result in arbitrary command execution as the user account running the Dimension WebUI process.