CVE-2026-78614: Dimension SQL Injection in Audit Report
Published Aug 27, 2026
·Updated
WatchGuard Dimension contains an authenticated SQL injection vulnerability in the audit report feature which allows an authenticated user with report administration permissions gain arbitrary command execution as the Dimension WebUI process user by sending specially crafted requests.
Affected Software
1 affected component
WatchGuard WatchGuard Dimension
Event History
Aug 27, 2026
CVE Published
via MITRE·11:26 PM
Data Sourced
via MITRE·11:26 PM
RemedyDescriptionWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The attacker must be authenticated and have report administration permissions in WatchGuard Dimension.
2
What account context would command execution use?
Commands execute as the Dimension WebUI process user.