CVE-2026-86135#
Dimension CSRF Vulnerability in Database Snapshot Creation Allows Denial of Service
Summary #
A Cross-Site Request Forgery (CSRF) vulnerability in WatchGuard Dimension's database snapshot creation feature allows a remote attacker to trigger unauthorized snapshot creation by tricking an authenticated administrator into visiting a specially crafted web page.
Impact: By repeatedly triggering the database snapshot feature without the administrator's consent, an attacker can cause an uncontrolled accumulation of snapshot files, exhausting available disk space and resulting in degraded performance, system instability, or denial of service.
Product status #
| Product | Affected | Not affected |
|---|---|---|
| Dimension | >= 2.0, < 2.3.1 | >= 2.3.1 |
Weakness Type and Impact #
Exploitation Status #
WatchGuard is not aware of any exploitation of this vulnerability in the wild.
Solution #
Dimension 2.3.1
References #
Credits #
- Simone Paganessi (https://www.linkedin.com/in/simonepaganessi)finder