# CVE-2026-86135

## Summary

- **CVE ID:** CVE-2026-86135
- **Severity:** HIGH
- **CVSS Score:** 7 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N)
- **CWE:** CWE-352, CWE-400
- **Published:** Sep 8, 2026
- **Last Modified:** Sep 8, 2026

## Description

A Cross-Site Request Forgery (CSRF) vulnerability in WatchGuard Dimension's database snapshot creation feature allows a remote attacker to trigger unauthorized snapshot creation by tricking an authenticated administrator into visiting a specially crafted web page.

## Affected Products

- WatchGuard — Dimension (2.0)

## References

- [CNA](https://psirt.watchguard.com/CVE-2026-86135)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.16%
- **EPSS Percentile:** 5.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._