CVE-2026-78616#
Dimension Stored XSS via Trusted CA Certificate Configuration
Summary #
A Stored Cross-Site Scripting (XSS) vulnerability in WatchGuard Dimension's Trusted CA certificate configuration allows an authenticated administrator to execute arbitrary JavaScript in another authenticated administrator's web browser by saving a carefully crafted certificate.
Impact: An attacker who can get an administrator to import a malicious CA certificate, or a malicious administrator targeting another administrator, can execute arbitrary JavaScript in the Dimension Web UI origin. This can be used to read same-origin administrative pages, issue authenticated requests as the victim administrator, and chain with other state-changing administrative actions.
Product status #
| Product | Affected | Not affected |
|---|---|---|
| Dimension | >= 2.0, < 2.3.1 | >= 2.3.1 |
Weakness Type and Impact #
Exploitation Status #
WatchGuard is not aware of any exploitation of this vulnerability in the wild.
Solution #
Dimension 2.3.1
References #
Credits #
- Yukusawa18finder