CVE-2026-78498

Dimension Server-Side Request Forgery via Email Server Test Settings

Medium 5.1 CVSS v4.0 › Published 2026-08-27Updated 2026-08-27

Summary #

A server-side request forgery (SSRF) vulnerability WatchGuard Dimension Email Server Test configuration allows an authenticated privileged attacker to enumerate exposed network services on adjacent network systems.

Impact: An authenticated attacker can abuse the Dimension application server as a proxy to reach internal network zones, bypassing network segmentation controls. This enables internal network reconnaissance (mapping internal hosts and open ports from the Dimension host's vantage point) and can assist in planning lateral movement and identifying vulnerable internal services for further exploitation.

Product status #

ProductAffectedNot affected
Dimension>= 2.0, < 2.3.1>= 2.3.1

Weakness Type and Impact #

  • CWECWE-918Server-Side Request Forgery (SSRF)
  • CAPECCAPEC-664Server Side Request Forgery

Exploitation Status #

WatchGuard is not aware of any exploitation of this vulnerability in the wild.

Solution #

Dimension 2.3.1

References #

    Credits #

    • Simone Paganessi (https://www.linkedin.com/in/simonepaganessi)finder