CVE-2026-78616: Dimension Stored XSS via Trusted CA Certificate Configuration
A Stored Cross-Site Scripting (XSS) vulnerability in WatchGuard Dimension's Trusted CA certificate configuration allows an authenticated administrator to execute arbitrary JavaScript in another authenticated administrator's web browser by saving a carefully crafted certificate.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Update WatchGuard Dimension Trusted CA certificate configuration to prevent Stored XSS via a crafted certificate (vulnerable in Dimension 2.3.1).
Event History
Frequently Asked Questions
Does exploitation require prior access to the management interface?
Yes. The attacker must be an authenticated administrator who can save a crafted certificate in the Trusted CA certificate configuration.
Which users are exposed to the stored script?
Other authenticated administrators who access the affected web interface can have arbitrary JavaScript executed in their browser.