CVE-2026-78618#
Dimension Business Logic Flaw Allows Chained Backend Object Operations
Summary #
A business logic flaw in WatchGuard Dimension allows an authenticated administrator to trigger multiple backend operations within a single logical flow by sending a specially crafted request.
Impact: This issue could allow unauthorized execution of multiple backend operations, potentially leading to state manipulation, privilege abuse, or bypass of intended workflow restrictions. The vulnerability stems from improper validation and isolation of user-controlled object data across requests.
Product status #
| Product | Affected | Not affected |
|---|---|---|
| Dimension | >= 2.0, < 2.3.1 | >= 2.3.1 |
Weakness Type and Impact #
Exploitation Status #
WatchGuard is not aware of any exploitation of this vulnerability in the wild.
Solution #
Dimension 2.3.1
References #
Credits #
- Cody Sixteenfinder