CVE-2026-78610

Dimension CSRF Vulnerability in Administrator Passphrase Change Endpoint

High 8.4 CVSS v4.0 › Published 2026-08-27Updated 2026-08-27

Summary #

WatchGuard Dimension's Web UI exposes an administrator passphrase change action that lacks CSRF protection. An attacker who can induce an authenticated global administrator's browser to visit a crafted link or page can change that administrator's passphrase to an attacker-chosen value without the administrator's consent.

Impact: A successful attack allows an attacker to change the Dimension global administrator's passphrase to a value of the attacker's choosing. If the attacker can also reach the Dimension Web UI, this leads to full administrator account takeover. Even without direct access to the Web UI, the attack can lock out legitimate administrators and disrupt management of Dimension, its reporting, log server configuration, user/role administration, and connected WatchGuard infrastructure.

Product status #

ProductAffectedNot affected
Dimension>= 2.0, < 2.3.1>= 2.3.1

Weakness Type and Impact #

  • CWECWE-352Cross-Site Request Forgery (CSRF)
  • CAPECCAPEC-62Cross Site Request Forgery

Exploitation Status #

WatchGuard is not aware of any exploitation of this vulnerability in the wild.

Solution #

Dimension 2.3.1

References #

    Credits #

    • Yukusawa18finder