CVE-2026-78610: Dimension CSRF Vulnerability in Administrator Passphrase Change Endpoint
Published Aug 27, 2026
·Updated
WatchGuard Dimension's Web UI exposes an administrator passphrase change action that lacks CSRF protection. An attacker who can induce an authenticated global administrator's browser to visit a crafted link or page can change that administrator's passphrase to an attacker-chosen value without the administrator's consent.
Affected Software
1 affected component
WatchGuard WatchGuard Dimension
Event History
Aug 27, 2026
CVE Published
via MITRE·11:26 PM
Data Sourced
via MITRE·11:26 PM
RemedyDescriptionWeakness
Frequently Asked Questions
1
Which users are exposed to this issue?
Global administrators are exposed when they are authenticated to the WatchGuard Dimension Web UI and can be induced to visit an attacker-crafted link or page.
2
What does an attacker need to exploit the issue?
The attacker must be able to cause an authenticated global administrator's browser to load crafted content. The attacker can then set that administrator's passphrase to a value of the attacker's choosing.