CVE-2026-78174

WatchGuard Dimension Session Hijack via Exposed Session Tokens in Diagnostic Logs

Critical 9.3 CVSS v4.0 › Published 2026-08-27Updated 2026-08-27

Summary #

WatchGuard Dimension records unredacted session identifiers for logged-in users in its web UI diagnostic log. A low-privileged Dimension Administrator can retrieve this log and extract a Super Administrator's session token while that administrator is logged in, enabling account takeover.

Impact: By harvesting the Super Administrator's session ID and CSRF token from the diagnostic log, an authenticated low-privileged Dimension Administrator can fully impersonate the Super Administrator, bypassing all access control restrictions. This allows the attacker to access and modify the Access Management section, create, delete, or alter any user or group, change system-wide configuration, lock out legitimate administrators, and gain persistent full administrative control over the Dimension appliance.

Product status #

ProductAffectedNot affected
Dimension>= 2.0, < 2.3.1>= 2.3.1

Weakness Type and Impact #

  • CWECWE-200Exposure of Sensitive Information to an Unauthorized Actor
  • CWECWE-269Improper Privilege Management
  • CWECWE-532Insertion of Sensitive Information into Log File
  • CAPECCAPEC-37Retrieve Embedded Sensitive Data
  • CAPECCAPEC-593Session Hijacking

Exploitation Status #

WatchGuard is not aware of any exploitation of this vulnerability in the wild.

Solution #

Dimension 2.3.1

References #

    Credits #

    • Simone Paganessi (https://www.linkedin.com/in/simonepaganessi)finder