CVE-2026-78610: Dimension CSRF Vulnerability in Administrator Passphrase Change Endpoint

Published Aug 27, 2026
·
Updated

WatchGuard Dimension's Web UI exposes an administrator passphrase change action that lacks CSRF protection. An attacker who can induce an authenticated global administrator's browser to visit a crafted link or page can change that administrator's passphrase to an attacker-chosen value without the administrator's consent.

Affected Software

1 affected component
WatchGuard WatchGuard Dimension

Event History

Aug 27, 2026
CVE Published
via MITRE·11:26 PM
Data Sourced
via MITRE·11:26 PM
RemedyDescriptionWeakness

Frequently Asked Questions

1

Which users are exposed to this issue?

Global administrators are exposed when they are authenticated to the WatchGuard Dimension Web UI and can be induced to visit an attacker-crafted link or page.

2

What does an attacker need to exploit the issue?

The attacker must be able to cause an authenticated global administrator's browser to load crafted content. The attacker can then set that administrator's passphrase to a value of the attacker's choosing.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203