CVE-2026-86135

Dimension CSRF Vulnerability in Database Snapshot Creation Allows Denial of Service

High 7.0 CVSS v4.0 › Published 2026-09-08Updated 2026-09-08

Summary #

A Cross-Site Request Forgery (CSRF) vulnerability in WatchGuard Dimension's database snapshot creation feature allows a remote attacker to trigger unauthorized snapshot creation by tricking an authenticated administrator into visiting a specially crafted web page.

Impact: By repeatedly triggering the database snapshot feature without the administrator's consent, an attacker can cause an uncontrolled accumulation of snapshot files, exhausting available disk space and resulting in degraded performance, system instability, or denial of service.

Product status #

ProductAffectedNot affected
Dimension>= 2.0, < 2.3.1>= 2.3.1

Weakness Type and Impact #

  • CWECWE-352Cross-Site Request Forgery (CSRF)
  • CWECWE-400Uncontrolled Resource Consumption
  • CAPECCAPEC-62Cross Site Request Forgery

Exploitation Status #

WatchGuard is not aware of any exploitation of this vulnerability in the wild.

Solution #

Dimension 2.3.1

References #

    Credits #

    • Simone Paganessi (https://www.linkedin.com/in/simonepaganessi)finder