CVE-2026-78174: WatchGuard Dimension Session Hijack via Exposed Session Tokens in Diagnostic Logs
WatchGuard Dimension records unredacted session identifiers for logged-in users in its web UI diagnostic log. A low-privileged Dimension Administrator can retrieve this log and extract a Super Administrator's session token while that administrator is logged in, enabling account takeover.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
A low-privileged Dimension Administrator can exploit it by retrieving the web UI diagnostic log. Exploitation depends on a Super Administrator being logged in so that the administrator's session token is present in the log.
What is the impact if exploitation succeeds?
The low-privileged administrator can extract the Super Administrator's unredacted session token from the diagnostic log and use it to take over that account.
How can I determine whether my environment is exposed?
Check whether users with the Dimension Administrator role can retrieve web UI diagnostic logs and whether those logs contain unredacted session identifiers for logged-in users. Exposure is particularly relevant when Super Administrators use the web UI while such logs are accessible.