CVE-2026-78614

Dimension SQL Injection in Audit Report

High 8.6 CVSS v4.0 › Published 2026-08-27Updated 2026-08-27

Summary #

WatchGuard Dimension contains an authenticated SQL injection vulnerability in the audit report feature which allows an authenticated user with report administration permissions gain arbitrary command execution as the Dimension WebUI process user by sending specially crafted requests.

Impact: An authenticated Dimension administrator can exploit the SQL injection to execute stacked SQL statements with PostgreSQL superuser privileges, read and write arbitrary files within the database process's permissions, and achieve operating system command execution as the wgadmin service user by planting a malicious server-side session file that is later deserialized. This results in full compromise of confidentiality, integrity, and availability of the Dimension appliance.

Product status #

ProductAffectedNot affected
Dimension>= 2.0, < 2.3.1>= 2.3.1

Weakness Type and Impact #

  • CWECWE-89Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
  • CWECWE-502Deserialization of Untrusted Data
  • CAPECCAPEC-66SQL Injection
  • CAPECCAPEC-586Object Injection

Exploitation Status #

WatchGuard is not aware of any exploitation of this vulnerability in the wild.

Solution #

Dimension 2.3.1

References #

    Credits #

    • Yukusawa18finder