CVE-2026-78103
Deferred Deferred - Pending Action

Authenticated Configuration Bypass in WatchGuard Dimension

Vulnerability report for CVE-2026-78103, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-28

Last updated on: 2026-08-28

Assigner: WatchGuard Technologies, Inc.

Description

WatchGuard Dimension provides a client-side lock/unlock UI control for management changes. The server-side configuration endpoint does not enforce this lock/unlock workflow state, allowing an authenticated administrator to submit configuration changes directly to the endpoint without first completing the UI unlock step. This allows an authenticated read-write administrator session to bypass the intended editing workflow and overwrite configuration changes being made by another concurrent administrator session.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-28
Last Modified
2026-08-28
Generated
2026-09-17
AI Q&A
2026-08-28
EPSS Evaluated
2026-09-15
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
watchguard dimension From 2.0 (inc) to 2.3.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-841 The product supports a session in which more than one behavior must be performed by an actor, but it does not properly ensure that the actor performs the behaviors in the required sequence.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in WatchGuard Dimension allows an authenticated administrator to bypass the intended lock/unlock workflow for configuration changes. The server-side endpoint does not enforce the UI workflow state, enabling direct submission of changes without unlocking, which can overwrite concurrent administrator edits.

Detection Guidance

To detect this vulnerability, check if your WatchGuard Dimension version is between 2.0 and less than 2.3.1. Verify if multiple administrators can submit configuration changes simultaneously without proper lock enforcement. Review logs for unauthorized direct endpoint submissions bypassing the UI workflow.

Impact Analysis

It can lead to configuration conflicts or overwrites by unauthorized concurrent changes, undermining system integrity. While it doesn't grant extra access, it disrupts intended workflows and may cause unintended system behavior or data loss.

Compliance Impact

This vulnerability undermines audit trail integrity by allowing unauthorized configuration changes without proper workflow enforcement. For GDPR, it risks non-compliance with Article 32 (security of processing) due to lack of proper access controls. For HIPAA, it may violate 45 CFR Β§164.312(a)(1) (access control) by bypassing intended administrative workflows.

Mitigation Strategies

Upgrade WatchGuard Dimension to version 2.3.1 or later to address the vulnerability. Ensure only authorized administrators have read-write access and monitor for unauthorized configuration changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78103. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart