CVE-2026-78618

Dimension Business Logic Flaw Allows Chained Backend Object Operations

Medium 6.9 CVSS v4.0 › Published 2026-08-27Updated 2026-08-27

Summary #

A business logic flaw in WatchGuard Dimension allows an authenticated administrator to trigger multiple backend operations within a single logical flow by sending a specially crafted request.

Impact: This issue could allow unauthorized execution of multiple backend operations, potentially leading to state manipulation, privilege abuse, or bypass of intended workflow restrictions. The vulnerability stems from improper validation and isolation of user-controlled object data across requests.

Product status #

ProductAffectedNot affected
Dimension>= 2.0, < 2.3.1>= 2.3.1

Weakness Type and Impact #

Exploitation Status #

WatchGuard is not aware of any exploitation of this vulnerability in the wild.

Solution #

Dimension 2.3.1

References #

    Credits #

    • Cody Sixteenfinder