CVE-2026-78500

Dimension Blind SSRF via Database Test Connection Feature

Medium 5.1 CVSS v4.0 › Published 2026-08-27Updated 2026-08-27

Summary #

A blind server-side request forgery (SSRF) vulnerability WatchGuard Dimension Database Server Test configuration allows an authenticated privileged attacker to enumerate exposed network services on adjacent network systems.

Impact: An authenticated administrator can abuse the database connection test feature to probe internal network hosts and infer reachability based on response timing, enabling internal network mapping, discovery of reachable internal services and IP ranges, and enumeration of internal infrastructure that would otherwise not be accessible to the attacker.

Product status #

ProductAffectedNot affected
Dimension>= 2.0, < 2.3.1>= 2.3.1

Weakness Type and Impact #

  • CWECWE-208Observable Timing Discrepancy
  • CWECWE-918Server-Side Request Forgery (SSRF)
  • CAPECCAPEC-462Cross-Domain Search Timing
  • CAPECCAPEC-664Server Side Request Forgery

Exploitation Status #

WatchGuard is not aware of any exploitation of this vulnerability in the wild.

Solution #

Dimension 2.3.1

References #

    Credits #

    • Simone Paganessi (https://www.linkedin.com/in/simonepaganessi)finder