CVE-2026-78103
Dimension Log Server Configuration Lock Bypass Vulnerability
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
WatchGuard Dimension provides a client-side lock/unlock UI control for management changes. The server-side configuration endpoint does not enforce this lock/unlock workflow state, allowing an authenticated administrator to submit configuration changes directly to the endpoint without first completing the UI unlock step. This allows an authenticated read-write administrator session to bypass the intended editing workflow and overwrite configuration changes being made by another concurrent administrator session.
| CWE | CWE-841 |
| Vendor | watchguard |
| Product | dimension |
| Published | Aug 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for watchguard dimension
Be the first to know when new unknown vulnerabilities affecting watchguard dimension are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
WatchGuard / Dimension
2.0 < 2.3.1
References
Credits
Simone Paganessi (https://www.linkedin.com/in/simonepaganessi)