CVE-2026-78195

Dimension Stored XSS via Backup Historical Data Feature

Medium 5.1 CVSS v4.0 › Published 2026-08-27Updated 2026-08-27

Summary #

A Cross-Site Scripting (XSS) vulnerability in the WatchGuard Dimension Backup Historical Data feature allows an authenticated administrator user to execute arbitrary JavaScript in another user's browser.

Impact: An authenticated attacker with low privileges can achieve persistent stored cross-site scripting that executes in the context of other Dimension users, including administrators, when they browse the tasks listing page. This can lead to session/token theft, unauthorized actions performed on behalf of the victim, UI manipulation, and further compromise of the Dimension administrative console.

Product status #

ProductAffectedNot affected
Dimension>= 2.0, < 2.3.1>= 2.3.1

Weakness Type and Impact #

  • CWECWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
  • CAPECCAPEC-63Cross-Site Scripting (XSS)
  • CAPECCAPEC-592Stored XSS

Exploitation Status #

WatchGuard is not aware of any exploitation of this vulnerability in the wild.

Solution #

Dimension 2.3.1

References #

    Credits #

    • Simone Paganessi (https://www.linkedin.com/in/simonepaganessi)finder