CVE-2026-86135 PUBLISHED

Dimension CSRF Vulnerability in Database Snapshot Creation Allows Denial of Service

Assigner: WatchGuard
Reserved: 05.09.2026 Published: 08.09.2026 Updated: 08.09.2026

A Cross-Site Request Forgery (CSRF) vulnerability in WatchGuard Dimension's database snapshot creation feature allows a remote attacker to trigger unauthorized snapshot creation by tricking an authenticated administrator into visiting a specially crafted web page.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
CVSS Score: 7

Product Status

Vendor WatchGuard
Product Dimension
Versions Default: unaffected
  • affected from 2.0 to 2.3.1 (excl.)

Exploits

WatchGuard is not aware of any exploitation of this vulnerability in the wild.

Solutions

Dimension 2.3.1

Credits

  • Simone Paganessi (https://www.linkedin.com/in/simonepaganessi) finder

References

Problem Types

  • CWE-352 CWE
  • CWE-400 CWE