CVE-2026-78495

Dimension Server-Side Request Forgery via Remote Backup Connection Test

Medium 5.3 CVSS v4.0 › Published 2026-08-27Updated 2026-08-27

Summary #

A server-side request forgery (SSRF) vulnerability WatchGuard Dimension Remote Backup Connection Test configuration allows an authenticated privileged attacker to enumerate exposed network services on adjacent network systems.

Impact: An authenticated attacker can leverage the remote backup connection test to perform internal network reconnaissance and port scanning from the Dimension server's network vantage point, mapping hosts and services that are otherwise inaccessible externally. This information can be used to identify internal management interfaces or vulnerable services and to plan further lateral movement or targeted exploitation within the internal network.

Product status #

ProductAffectedNot affected
Dimension>= 2.0, < 2.3.1>= 2.3.1

Weakness Type and Impact #

  • CWECWE-918Server-Side Request Forgery (SSRF)
  • CAPECCAPEC-664Server Side Request Forgery

Exploitation Status #

WatchGuard is not aware of any exploitation of this vulnerability in the wild.

Solution #

Dimension 2.3.1

References #

    Credits #

    • Simone Paganessi (https://www.linkedin.com/in/simonepaganessi)finder