Skip to content

PSIRT WatchGuard CVE-2026-78174

psirt.watchguard.com August 29, 2026

WatchGuard Dimension records unredacted session identifiers for logged-in users in its web UI diagnostic log. A low-privileged Dimension Administrator can retrieve this log and extract a Super Administrator's session token while that administrator is logged in, enabling account takeover.

Impact: By harvesting the Super Administrator's session ID and CSRF token from the diagnostic log, an authenticated low-privileged Dimension Administrator can fully impersonate the Super Administrator, bypassing all access control restrictions. This allows the attacker to access and modify the Access Management section, create, delete, or alter any user or group, change system-wide configuration, lock out legitimate administrators, and gain persistent full administrative control over the Dimension appliance.