← Volver al buscador de CVEs

CVE-2026-78612

WatchGuard Dimension

Descripción

WatchGuard Dimension contains an authenticated SQL injection vulnerability in the scheduled report feature which allows an authenticated user with report administration permissions gain arbitrary command execution as the Dimension WebUI process user by sending specially crafted requests.

CVSS 8.6EPSS 0.697%Riesgo 0.91
Ver fuente
Publicación
2026-08-28 02:16:23
Versiones afectadas
unknown
Tipo
Aplicación web
Última modificación
2026-08-28 02:16:23
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X