CVE-2026-78617
WatchGuard Dimension Web UI Authentication Brute-Force Due to Missing Rate Limiting
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
WatchGuard Dimension's web login endpoint does not enforce effective rate-limiting or account lockout by default allowing a remote attacker to perform automated password guessing against user accounts. If the account lockout setting is enabled, brute-force attempts are blocked after a defined number of failed attempts, but this setting is not enabled by default.
| CWE | CWE-203 CWE-307 |
| Vendor | watchguard |
| Product | dimension |
| Published | Aug 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for watchguard dimension
Be the first to know when new unknown vulnerabilities affecting watchguard dimension are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
WatchGuard / Dimension
2.0 < 2.3.1
References
Credits
Simone Paganessi (https://www.linkedin.com/in/simonepaganessi)