CVE-2026-78610
Deferred Deferred - Pending Action

CSRF Vulnerability in WatchGuard Dimension Web UI

Vulnerability report for CVE-2026-78610, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-28

Last updated on: 2026-08-28

Assigner: WatchGuard Technologies, Inc.

Description

WatchGuard Dimension's Web UI exposes an administrator passphrase change action that lacks CSRF protection. An attacker who can induce an authenticated global administrator's browser to visit a crafted link or page can change that administrator's passphrase to an attacker-chosen value without the administrator's consent.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-28
Last Modified
2026-08-28
Generated
2026-09-17
AI Q&A
2026-08-28
EPSS Evaluated
2026-09-15
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
watchguard dimension From 2.0 (inc) to 2.3.1 (exc)
watchguard dimension *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-352 The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Cross-Site Request Forgery (CSRF) flaw in WatchGuard Dimension's Web UI. It allows an attacker to change an administrator's passphrase without their consent by tricking them into visiting a malicious link or page while authenticated.

Detection Guidance

To detect this vulnerability, check if WatchGuard Dimension versions are between 2.0 and below 2.3.1. Review Web UI logs for unauthorized passphrase change requests or unusual administrator activity. Monitor network traffic for suspicious links or pages that could trigger CSRF attacks.

Impact Analysis

An attacker could take over the administrator account, lock out legitimate users, disrupt management functions like reporting and user administration, or affect connected WatchGuard infrastructure. This could lead to full system compromise or operational disruption.

Compliance Impact

This vulnerability could lead to unauthorized access or changes to sensitive data, potentially violating compliance requirements for data protection and access control in standards like GDPR and HIPAA.

Mitigation Strategies

Immediately upgrade WatchGuard Dimension to version 2.3.1 or later. Disable or restrict access to the Web UI from untrusted networks. Implement additional CSRF protections like tokens or referrer checks if possible. Review and audit administrator accounts for unauthorized changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78610. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart