WatchGuard Dimension contains an authenticated SQL injection vulnerability in the log viewer feature which allows an authenticated user with report administration permissions gain arbitrary command execution as the Dimension WebUI process user by sending specially crafted requests.
CVSS
No CVSS.
References
| Link | Resource |
|---|---|
| https://psirt.watchguard.com/CVE-2026-78613 |
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-28 02:16
Updated : 2026-08-28 20:19
NVD link : CVE-2026-78613
Mitre link : CVE-2026-78613
CVE.ORG link : CVE-2026-78613
JSON object : View
Products Affected
No product.
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
