CVE-2026-78174
WatchGuard Dimension Session Hijack via Exposed Session Tokens in Diagnostic Logs
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
WatchGuard Dimension records unredacted session identifiers for logged-in users in its web UI diagnostic log. A low-privileged Dimension Administrator can retrieve this log and extract a Super Administrator's session token while that administrator is logged in, enabling account takeover.
| CWE | CWE-200 CWE-269 CWE-532 |
| Vendor | watchguard |
| Product | dimension |
| Published | Aug 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for watchguard dimension
Be the first to know when new unknown vulnerabilities affecting watchguard dimension are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
WatchGuard / Dimension
2.0 < 2.3.1
References
Credits
Simone Paganessi (https://www.linkedin.com/in/simonepaganessi)