CVE-2026-78617: WatchGuard Dimension Web UI Authentication Brute-Force Due to Missing Rate Limiting

Published Aug 27, 2026
·
Updated

WatchGuard Dimension's web login endpoint does not enforce effective rate-limiting or account lockout by default allowing a remote attacker to perform automated password guessing against user accounts. If the account lockout setting is enabled, brute-force attempts are blocked after a defined number of failed attempts, but this setting is not enabled by default.

Affected Software

1 affected component
WatchGuard Dimension Web UI

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Enable the account lockout setting for WatchGuard Dimension web login so brute-force attempts are blocked after a defined number of failed attempts (the setting is not enabled by default).

    WatchGuard Dimension Web UI authentication account lockout (enabled) = enabled
  2. Compensating control

    Add/enforce effective rate-limiting on the WatchGuard Dimension web login endpoint so automated password guessing is throttled, since the endpoint does not enforce effective rate-limiting by default.

Event History

Aug 27, 2026
CVE Published
via MITRE·11:26 PM
Data Sourced
via MITRE·11:26 PM
RemedyDescriptionWeakness

Frequently Asked Questions

1

Which deployments are exposed by default?

WatchGuard Dimension Web UI deployments are exposed when the account lockout setting remains at its default disabled state. In that configuration, the login endpoint does not effectively rate-limit automated password guesses.

2

What does an attacker need to exploit this issue?

An attacker needs remote access to the web login endpoint and can automate password guessing against user accounts. The provided information does not identify any additional prerequisite.

3

What mitigation is available if patching is not immediately possible?

Enable the account lockout setting. When enabled, it blocks brute-force attempts after a defined number of failed login attempts.

4

How can administrators determine whether they are affected?

Check whether account lockout is enabled in the WatchGuard Dimension Web UI configuration. Systems with account lockout disabled are in the default affected configuration.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203