CVE-2026-78495
Deferred Deferred - Pending Action

Authenticated SSRF in WatchGuard Dimension via Remote Backup Connection Test

Vulnerability report for CVE-2026-78495, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-28

Last updated on: 2026-08-28

Assigner: WatchGuard Technologies, Inc.

Description

A server-side request forgery (SSRF) vulnerability WatchGuard Dimension Remote Backup Connection Test configuration allows an authenticated privileged attacker to enumerate exposed network services on adjacent network systems.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-28
Last Modified
2026-08-28
Generated
2026-09-17
AI Q&A
2026-08-28
EPSS Evaluated
2026-09-15
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
watchguard dimension From 2.0 (inc) to 2.3.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a server-side request forgery (SSRF) vulnerability in WatchGuard Dimension software. It exists in the Remote Backup Connection Test configuration. An authenticated privileged attacker can exploit it to perform internal network reconnaissance and port scanning from the Dimension server's network. This allows mapping hosts and services not accessible externally, potentially identifying internal management interfaces or vulnerable services for further exploitation or lateral movement.

Detection Guidance

To detect this SSRF vulnerability in WatchGuard Dimension, check if your system is running a vulnerable version (>=2.0 and <2.3.1). Monitor network traffic from the Dimension server for unusual outbound requests to internal or external systems. Inspect logs for Remote Backup Connection Test configurations that may indicate exploitation attempts.

Impact Analysis

An attacker could use this vulnerability to scan your internal network, identify exposed services, and potentially exploit them. This could lead to unauthorized access to sensitive systems, data breaches, or lateral movement within your network. The impact depends on your internal network configuration and the services running.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, which may violate compliance requirements under GDPR, HIPAA, or other regulations. Organizations could face penalties for failing to protect personal or health information due to insufficient network security controls.

Mitigation Strategies

Immediately upgrade WatchGuard Dimension to version 2.3.1 or later to patch the vulnerability. If upgrading is not possible, restrict network access to the Dimension server and disable the Remote Backup Connection Test feature until patched. Review and monitor network traffic for signs of exploitation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78495. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart