CVE-2026-78617
Deferred Deferred - Pending Action

WatchGuard Dimension Default Credential Brute Force

Vulnerability report for CVE-2026-78617, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-28

Last updated on: 2026-08-28

Assigner: WatchGuard Technologies, Inc.

Description

WatchGuard Dimension's web login endpoint does not enforce effective rate-limiting or account lockout by default allowing a remote attacker to perform automated password guessing against user accounts. If the account lockout setting is enabled, brute-force attempts are blocked after a defined number of failed attempts, but this setting is not enabled by default.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-28
Last Modified
2026-08-28
Generated
2026-09-17
AI Q&A
2026-08-28
EPSS Evaluated
2026-09-15
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
watchguard dimension From 2.0 (inc) to 2.3.1 (exc)
watchguard dimension 2.3.1
watchguard dimension *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-203 The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.
CWE-307 The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects WatchGuard Dimension's web login endpoint which lacks effective rate-limiting or account lockout by default. This allows remote attackers to perform automated password guessing attacks against user accounts, including administrative or operator accounts. If account lockout is enabled, brute-force attempts are blocked after a set number of failed attempts, but this setting is not enabled by default.

Detection Guidance

Monitor login attempts for repeated failed authentication attempts on WatchGuard Dimension's web login endpoint. Check logs for unusual activity such as multiple rapid login requests from the same IP address or user account. Enable and review audit logs for signs of brute-force attempts.

Impact Analysis

An unauthenticated attacker could conduct brute-force or credential-stuffing attacks, potentially leading to full account takeover and compromise of the Dimension server, its logs, and other integrated security tools.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, which may violate compliance requirements under GDPR and HIPAA. GDPR mandates strong authentication and protection against brute-force attacks to safeguard personal data, while HIPAA requires secure access controls for protected health information. The lack of rate-limiting or account lockout increases the risk of data breaches.

Mitigation Strategies

Immediately enable account lockout settings in WatchGuard Dimension to block brute-force attempts after a defined number of failed login attempts. Upgrade to Dimension version 2.3.1 or later to address the vulnerability. Restrict access to the web login endpoint via network controls or firewalls.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78617. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart