CVE-2026-78047

Dimension Stored XSS in Scheduled Report Task

Medium 5.1 CVSS v4.0 › Published 2026-08-27Updated 2026-08-27

Summary #

A stored cross-site scripting (XSS) vulnerability in WatchGuard Dimension's task scheduling feature allows a low-privileged authenticated administrator to inject arbitrary HTML/JavaScript into these fields, which then executes in the browser session of any other user.

Impact: Successful exploitation allows an attacker with low-privileged access to execute arbitrary JavaScript in the browser context of other users who view the task listing page, including administrators. This can lead to theft of session cookies/tokens, performance of unauthorized actions on behalf of the victim, UI manipulation, and further persistent attacks, potentially resulting in privilege escalation and broader administrative compromise of the Dimension system.

Product status #

ProductAffectedNot affected
Dimension>= 2.0, < 2.3.1>= 2.3.1

Weakness Type and Impact #

  • CWECWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
  • CAPECCAPEC-63Cross-Site Scripting (XSS)
  • CAPECCAPEC-592Stored XSS

Exploitation Status #

WatchGuard is not aware of any exploitation of this vulnerability in the wild.

Solution #

Dimension 2.3.1

References #

    Credits #

    • Simone Paganessi (https://www.linkedin.com/in/simonepaganessi)finder