CVE-2026-78498#
Dimension Server-Side Request Forgery via Email Server Test Settings
Summary #
A server-side request forgery (SSRF) vulnerability WatchGuard Dimension Email Server Test configuration allows an authenticated privileged attacker to enumerate exposed network services on adjacent network systems.
Impact: An authenticated attacker can abuse the Dimension application server as a proxy to reach internal network zones, bypassing network segmentation controls. This enables internal network reconnaissance (mapping internal hosts and open ports from the Dimension host's vantage point) and can assist in planning lateral movement and identifying vulnerable internal services for further exploitation.
Product status #
| Product | Affected | Not affected |
|---|---|---|
| Dimension | >= 2.0, < 2.3.1 | >= 2.3.1 |
Weakness Type and Impact #
Exploitation Status #
WatchGuard is not aware of any exploitation of this vulnerability in the wild.
Solution #
Dimension 2.3.1
References #
Credits #
- Simone Paganessi (https://www.linkedin.com/in/simonepaganessi)finder