CVE-2026-78103

Dimension Log Server Configuration Lock Bypass Vulnerability

Medium 5.1 CVSS v4.0 › Published 2026-08-27Updated 2026-08-27

Summary #

WatchGuard Dimension provides a client-side lock/unlock UI control for management changes. The server-side configuration endpoint does not enforce this lock/unlock workflow state, allowing an authenticated administrator to submit configuration changes directly to the endpoint without first completing the UI unlock step. This allows an authenticated read-write administrator session to bypass the intended editing workflow and overwrite configuration changes being made by another concurrent administrator session.

Impact: An attacker who already holds an authenticated administrator session with read-write permissions can send configuration change requests directly to the Log Server configuration endpoint, bypassing the UI lock/unlock workflow. This does not grant any access beyond what the admin session already has, but it can result in one administrator's configuration changes overwriting or conflicting with another administrator's concurrent changes, undermining the integrity guarantee that the lock/unlock mechanism is intended to provide.

Product status #

ProductAffectedNot affected
Dimension>= 2.0, < 2.3.1>= 2.3.1

Weakness Type and Impact #

  • CWECWE-841Improper Enforcement of Behavioral Workflow
  • CAPECCAPEC-122Privilege Abuse

Exploitation Status #

WatchGuard is not aware of any exploitation of this vulnerability in the wild.

Solution #

Dimension 2.3.1

References #

    Credits #

    • Simone Paganessi (https://www.linkedin.com/in/simonepaganessi)finder