CVE-2026-78615: WatchGuard Dimension Reflected DOM-Based XSS in Report Detail Page
Published Aug 27, 2026
·Updated
A Reflected Cross-Site Scripting (XSS) vulnerability in WatchGuard Dimension's report detail page allows an attacker to execute arbitrary JavaScript in a authenticated user's browser with a specially crafted URL.
Affected Software
1 affected component
WatchGuard WatchGuard Dimension
Event History
Aug 27, 2026
CVE Published
via MITRE·11:26 PM
Data Sourced
via MITRE·11:26 PM
RemedyDescriptionWeakness
Frequently Asked Questions
1
Who can be targeted by this issue?
Authenticated WatchGuard Dimension users who open a specially crafted URL can have arbitrary JavaScript executed in their browser.
2
What does an attacker need to exploit it?
The attacker needs to cause an authenticated user to visit a specially crafted URL for the WatchGuard Dimension report detail page.