WatchGuard TechnologiesCVE-2026-78174
WatchGuard Technologies Dimension: information disclosure
Critical9.3CVE-2026-78174 · Published Aug 28, 2026
WatchGuard Dimension records unredacted session identifiers for logged-in users in its web UI diagnostic log. A low-privileged Dimension Administrator can retrieve this log and extract a Super Administrator's session token while that administrator is logged in, enabling account takeover.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Dimension Product | >= 2.0, < 2.3.1 | 2.3.1 |
Details and references
More WatchGuard Technologies advisories
All WatchGuard Technologies| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 28 | WatchGuard Technologies Dimension: SQL injection | High8.6 | 2.3.1 |
| Aug 28 | WatchGuard Technologies Dimension: cross-site scripting | Medium4.6 | 2.3.1 |
| Aug 28 | WatchGuard Technologies Dimension: cross-site scripting | Medium4.8 | 2.3.1 |
| Aug 28 | WatchGuard Technologies Dimension: observable discrepancy | Medium6.3 | 2.3.1 |
| Aug 28 | WatchGuard Technologies Dimension: improper access control | Medium6.9 | 2.3.1 |
| Aug 28 | WatchGuard Technologies Dimension: server-side request forgery | Medium5.3 | 2.3.1 |