๐Ÿ” CVE Alert

CVE-2026-78174

UNKNOWN 0.0

WatchGuard Dimension Session Hijack via Exposed Session Tokens in Diagnostic Logs

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

WatchGuard Dimension records unredacted session identifiers for logged-in users in its web UI diagnostic log. A low-privileged Dimension Administrator can retrieve this log and extract a Super Administrator's session token while that administrator is logged in, enabling account takeover.

CWE CWE-200 CWE-269 CWE-532
Vendor watchguard
Product dimension
Published Aug 27, 2026
Stay Ahead of the Next One

Get instant alerts for watchguard dimension

Be the first to know when new unknown vulnerabilities affecting watchguard dimension are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

WatchGuard / Dimension
2.0 < 2.3.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
psirt.watchguard.com: https://psirt.watchguard.com/CVE-2026-78174

Credits

Simone Paganessi (https://www.linkedin.com/in/simonepaganessi)