CVE-2026-78500#
Dimension Blind SSRF via Database Test Connection Feature
Summary #
A blind server-side request forgery (SSRF) vulnerability WatchGuard Dimension Database Server Test configuration allows an authenticated privileged attacker to enumerate exposed network services on adjacent network systems.
Impact: An authenticated administrator can abuse the database connection test feature to probe internal network hosts and infer reachability based on response timing, enabling internal network mapping, discovery of reachable internal services and IP ranges, and enumeration of internal infrastructure that would otherwise not be accessible to the attacker.
Product status #
| Product | Affected | Not affected |
|---|---|---|
| Dimension | >= 2.0, < 2.3.1 | >= 2.3.1 |
Weakness Type and Impact #
Exploitation Status #
WatchGuard is not aware of any exploitation of this vulnerability in the wild.
Solution #
Dimension 2.3.1
References #
Credits #
- Simone Paganessi (https://www.linkedin.com/in/simonepaganessi)finder