CVE-2026-78499

Dimension SSRF via FTP Server Test Connection

Medium 5.1 CVSS v4.0 › Published 2026-08-27Updated 2026-08-27

Summary #

A server-side request forgery (SSRF) vulnerability WatchGuard Dimension FTP Server Test configuration allows an authenticated privileged attacker to enumerate exposed network services on adjacent network systems.

Impact: An authenticated attacker can perform internal network discovery and host enumeration, identify live internal IP addresses and network ranges, map internal infrastructure through blind timing analysis, and gather intelligence to support lateral movement or chained attacks.

Product status #

ProductAffectedNot affected
Dimension>= 2.0, < 2.3.1>= 2.3.1

Weakness Type and Impact #

  • CWECWE-918Server-Side Request Forgery (SSRF)
  • CAPECCAPEC-664Server Side Request Forgery

Exploitation Status #

WatchGuard is not aware of any exploitation of this vulnerability in the wild.

Solution #

Dimension 2.3.1

References #

    Credits #

    • Simone Paganessi (https://www.linkedin.com/in/simonepaganessi)finder