CVE-2026-78616

Dimension Stored XSS via Trusted CA Certificate Configuration

Medium 4.8 CVSS v4.0 › Published 2026-08-27Updated 2026-08-27

Summary #

A Stored Cross-Site Scripting (XSS) vulnerability in WatchGuard Dimension's Trusted CA certificate configuration allows an authenticated administrator to execute arbitrary JavaScript in another authenticated administrator's web browser by saving a carefully crafted certificate.

Impact: An attacker who can get an administrator to import a malicious CA certificate, or a malicious administrator targeting another administrator, can execute arbitrary JavaScript in the Dimension Web UI origin. This can be used to read same-origin administrative pages, issue authenticated requests as the victim administrator, and chain with other state-changing administrative actions.

Product status #

ProductAffectedNot affected
Dimension>= 2.0, < 2.3.1>= 2.3.1

Weakness Type and Impact #

  • CWECWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
  • CAPECCAPEC-63Cross-Site Scripting (XSS)
  • CAPECCAPEC-592Stored XSS

Exploitation Status #

WatchGuard is not aware of any exploitation of this vulnerability in the wild.

Solution #

Dimension 2.3.1

References #

    Credits #

    • Yukusawa18finder