PSIRT WatchGuard CVE-2026-78174
WatchGuard Dimension records unredacted session identifiers for logged-in users in its web UI diagnostic log. A low-privileged Dimension Administrator can retrieve this log and extract a Super Administrator's session token while that administrator is logged in, enabling account takeover.
Impact: By harvesting the Super Administrator's session ID and CSRF token from the diagnostic log, an authenticated low-privileged Dimension Administrator can fully impersonate the Super Administrator, bypassing all access control restrictions. This allows the attacker to access and modify the Access Management section, create, delete, or alter any user or group, change system-wide configuration, lock out legitimate administrators, and gain persistent full administrative control over the Dimension appliance.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
