CVE-2026-78617#
WatchGuard Dimension Web UI Authentication Brute-Force Due to Missing Rate Limiting
Summary #
WatchGuard Dimension's web login endpoint does not enforce effective rate-limiting or account lockout by default allowing a remote attacker to perform automated password guessing against user accounts. If the account lockout setting is enabled, brute-force attempts are blocked after a defined number of failed attempts, but this setting is not enabled by default.
Impact: A remote unauthenticated attacker can conduct automated brute-force or credential-stuffing attacks against Dimension user accounts, including administrative or operator accounts, potentially leading to full account takeover and compromise of the Dimension server, its logs, and other integrated security tooling.
Product status #
| Product | Affected | Not affected |
|---|---|---|
| Dimension | >= 2.0, < 2.3.1 | >= 2.3.1 |
Weakness Type and Impact #
Exploitation Status #
WatchGuard is not aware of any exploitation of this vulnerability in the wild.
Solution #
Dimension 2.3.1
References #
Credits #
- Simone Paganessi (https://www.linkedin.com/in/simonepaganessi)finder