CVE-2026-78610
Dimension CSRF Vulnerability in Administrator Passphrase Change Endpoint
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
WatchGuard Dimension's Web UI exposes an administrator passphrase change action that lacks CSRF protection. An attacker who can induce an authenticated global administrator's browser to visit a crafted link or page can change that administrator's passphrase to an attacker-chosen value without the administrator's consent.
| CWE | CWE-352 |
| Vendor | watchguard |
| Product | dimension |
| Published | Aug 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for watchguard dimension
Be the first to know when new unknown vulnerabilities affecting watchguard dimension are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
WatchGuard / Dimension
2.0 < 2.3.1
References
Credits
Yukusawa18