CVE-2026-78174
Deferred Deferred - Pending Action

WatchGuard Dimension Session Token Exposure via Diagnostic Log

Vulnerability report for CVE-2026-78174, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-28

Last updated on: 2026-08-28

Assigner: WatchGuard Technologies, Inc.

Description

WatchGuard Dimension records unredacted session identifiers for logged-in users in its web UI diagnostic log. A low-privileged Dimension Administrator can retrieve this log and extract a Super Administrator's session token while that administrator is logged in, enabling account takeover.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-28
Last Modified
2026-08-28
Generated
2026-09-17
AI Q&A
2026-08-28
EPSS Evaluated
2026-09-15
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
watchguard dimension From 2.0 (inc) to 2.3.1 (exc)
watchguard dimension *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-532 The product writes sensitive information to a log file.
CWE-269 The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves WatchGuard Dimension software recording unredacted session identifiers for logged-in users in diagnostic logs. A low-privileged administrator can access these logs and extract a Super Administrator's session token while they are logged in, enabling account takeover.

Detection Guidance

Check WatchGuard Dimension diagnostic logs for unredacted session identifiers or tokens. Look for logs containing session IDs or CSRF tokens of Super Administrators while they are logged in. Verify if logs are accessible to low-privileged administrators.

Impact Analysis

An attacker could impersonate a Super Administrator, bypass access controls, modify system configurations, create or delete users, lock out legitimate administrators, and gain full administrative control over the Dimension appliance.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive administrative functions, potentially exposing personal data or protected health information. A low-privileged administrator could impersonate a Super Administrator, bypassing access controls and gaining full control over the system, which may violate GDPR's data protection requirements or HIPAA's access control mandates.

Mitigation Strategies
  • Upgrade WatchGuard Dimension to version 2.3.1 or later to address the vulnerability.
  • Restrict access to diagnostic logs to only necessary administrators.
  • Review logs for any unauthorized access or session token exposure.
  • Rotate all Super Administrator session tokens and CSRF tokens if logs were accessed.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78174. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart