CVE-2026-78610
8.4WatchGuard · Dimension
WatchGuard Dimension contains a cross-site request forgery vulnerability in the Web UI, allowing an attacker to change an administrator passphrase via a crafted link.
Executive summary
A high-severity cross-site request forgery vulnerability in WatchGuard Dimension allows an attacker to seize administrative control by forcing a passphrase reset.
Vulnerability
The application lacks CSRF protection on the administrator passphrase change action, which permits an attacker to perform unauthorized administrative modifications. This vulnerability requires an authenticated global administrator to be tricked into visiting a malicious site or link.
Business impact
This vulnerability poses a significant risk to organizational security, as it allows unauthorized actors to reset the credentials of global administrators. A successful exploit grants the attacker full administrative access to the Dimension instance, leading to potential data compromise, configuration tampering, and total loss of system integrity. With a CVSS score of 8.4, this issue is categorized as High severity and requires immediate remediation.
Remediation
Immediate Action: Update WatchGuard Dimension to version 2.3.1 or later as specified by the vendor.
Proactive Monitoring: Review administrative access logs for unusual login activity or passphrase modification events that do not correlate with known administrative actions.
Compensating Controls: Implement strict browser security policies and educate administrative staff on the risks of clicking untrusted links while logged into sensitive management interfaces. A Web Application Firewall (WAF) can also be configured to block suspicious cross-site requests.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the potential for complete administrative account compromise, this vulnerability presents an elevated risk to the security posture of the affected systems. Administrators must prioritize the application of the vendor-provided patch to version 2.3.1 to eliminate the underlying flaw. Until the update is deployed, ensure that administrative sessions are isolated and that staff exercise caution regarding external links while authenticated to the management console.
More WatchGuard CVEs
Sources
Originally found and disclosed by Yukusawa18, per the CVE Program record.