CVE-2026-86135: Dimension CSRF Vulnerability in Database Snapshot Creation Allows Denial of Service
A Cross-Site Request Forgery (CSRF) vulnerability in WatchGuard Dimension's database snapshot creation feature allows a remote attacker to trigger unauthorized snapshot creation by tricking an authenticated administrator into visiting a specially crafted web page.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WatchGuard Dimensionto a version that resolves this vulnerability.Fixed in 2.3.1
Event History
Frequently Asked Questions
Who is exposed to this issue?
WatchGuard Dimension deployments are exposed when an administrator is authenticated to the product's web interface and can be induced to visit a specially crafted web page.
What does an attacker need to exploit it?
The attacker needs to trick an authenticated administrator into visiting a malicious page. The description does not indicate that the attacker needs direct access to the Dimension interface or administrator credentials.
What is the practical impact of successful exploitation?
An attacker can cause unauthorized database snapshot creation. This can result in denial of service.