CVE-2026-78047: WatchGuard Dimension

Medium severity, CVSS 5.1. EPSS: 0.4% chance of exploitation in the next 30 days.

A stored cross-site scripting (XSS) vulnerability in WatchGuard Dimension's task scheduling feature allows a low-privileged authenticated administrator to inject arbitrary HTML/JavaScript into these fields, which then executes in the browser session of any other user.

Affected products

  • WatchGuard Dimension: from 2.0, before 2.3.1 (fixed in 2.3.1)

Published 2026-08-28. Last modified 2026-08-28.