CVE-2026-78500: Dimension Blind SSRF via Database Test Connection Feature
Published Aug 27, 2026
·Updated
A blind server-side request forgery (SSRF) vulnerability WatchGuard Dimension Database Server Test configuration allows an authenticated privileged attacker to enumerate exposed network services on adjacent network systems.
Affected Software
1 affected component
WatchGuard WatchGuard Dimension Database Server
Event History
Aug 27, 2026
CVE Published
via MITRE·11:26 PM
Data Sourced
via MITRE·11:26 PM
RemedyDescriptionWeakness
Frequently Asked Questions
1
Who can exploit this issue?
Exploitation requires an authenticated attacker with privileged access to the WatchGuard Dimension Database Server Test configuration.
2
What can an attacker do with successful exploitation?
The attacker can use the test configuration to make blind server-side requests and enumerate exposed network services on systems adjacent to the affected server.