CVE-2026-78615

WatchGuard Dimension Reflected DOM-Based XSS in Report Detail Page

Medium 4.6 CVSS v4.0 › Published 2026-08-27Updated 2026-08-27

Summary #

A Reflected Cross-Site Scripting (XSS) vulnerability in WatchGuard Dimension's report detail page allows an attacker to execute arbitrary JavaScript in a authenticated user's browser with a specially crafted URL.

Impact: A remote attacker can craft a link that, when clicked by an authenticated Dimension user with report access, executes arbitrary JavaScript in the context of the Dimension Web UI. This can be used to perform same-origin actions as the victim, read same-origin page data, or be chained with other state-changing endpoints or CSRF weaknesses in the Dimension Web UI. Exploitation requires the victim to be authenticated, hold report-viewing permission for the target device, and to open an attacker-supplied link.

Product status #

ProductAffectedNot affected
Dimension>= 2.0, < 2.3.1>= 2.3.1

Weakness Type and Impact #

  • CWECWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
  • CAPECCAPEC-63Cross-Site Scripting (XSS)
  • CAPECCAPEC-591Reflected XSS

Exploitation Status #

WatchGuard is not aware of any exploitation of this vulnerability in the wild.

Solution #

Dimension 2.3.1

References #

    Credits #

    • Yukusawa18finder