Description
WatchGuard Dimension provides a client-side lock/unlock UI control for management changes. The server-side configuration endpoint does not enforce this lock/unlock workflow state, allowing an authenticated administrator to submit configuration changes directly to the endpoint without first completing the UI unlock step. This allows an authenticated read-write administrator session to bypass the intended editing workflow and overwrite configuration changes being made by another concurrent administrator session.
Published: 2026-08-27
Score: 5.1 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

WatchGuard Dimension implements a client‑side lock/unlock UI to protect configuration changes, but the server‑side configuration endpoint does not enforce that workflow. An authenticated administrator can therefore submit configuration changes directly to the endpoint without completing the UI unlock step. This allows a read‑write administrator to bypass the intended editing workflow and overwrite configuration changes made by another concurrent administrator, potentially corrupting or inadvertently altering the system configuration.

Affected Systems

The vulnerability affects the WatchGuard Dimension appliance. All versions released before 2.3.1 are impacted. The vendor has issued a fix in Dimension 2.3.1.

Risk and Exploitability

The vulnerability is assigned a medium CVSS score of 5.1. EPSS information is not available and it is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attacker must be an authenticated administrator with read‑write privileges. The risk is moderate due to the requirement of valid credentials, but the impact on configuration integrity could lead to service disruptions or misconfiguration if an attacker intentionally modifies settings.

Generated by OpenCVE AI on August 28, 2026 at 07:29 UTC.

Remediation

Vendor Solution

Dimension 2.3.1


OpenCVE Recommended Actions

  • Upgrade to Dimension 2.3.1 or newer as released by WatchGuard
  • If possible, restrict direct POST access to the configuration endpoint or enforce lock validation on the API side
  • Enable audit logging of configuration changes and review for concurrent modification conflicts

Generated by OpenCVE AI on August 28, 2026 at 07:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description WatchGuard Dimension provides a client-side lock/unlock UI control for management changes. The server-side configuration endpoint does not enforce this lock/unlock workflow state, allowing an authenticated administrator to submit configuration changes directly to the endpoint without first completing the UI unlock step. This allows an authenticated read-write administrator session to bypass the intended editing workflow and overwrite configuration changes being made by another concurrent administrator session.
Title Dimension Log Server Configuration Lock Bypass Vulnerability
First Time appeared Watchguard
Watchguard dimension
Weaknesses CWE-841
CPEs cpe:2.3:a:watchguard:dimension:*:*:*:*:*:*:*:*
Vendors & Products Watchguard
Watchguard dimension
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Watchguard Dimension
cve-icon MITRE

Status: PUBLISHED

Assigner: WatchGuard

Published:

Updated: 2026-08-27T23:26:31.432Z

Reserved: 2026-08-22T17:36:37.256Z

Link: CVE-2026-78103

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-28T02:16:22.830

Modified: 2026-08-28T02:16:22.830

Link: CVE-2026-78103

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T07:30:07Z

Weaknesses
  • CWE-841

    Improper Enforcement of Behavioral Workflow