Description
WatchGuard Dimension records unredacted session identifiers for logged-in users in its web UI diagnostic log. A low-privileged Dimension Administrator can retrieve this log and extract a Super Administrator's session token while that administrator is logged in, enabling account takeover.
Published: 2026-08-27
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

WatchGuard Dimension records session identifiers for logged-in users in its web UI diagnostic log without redaction. A low‑privileged Administrator can read this log while a Super Administrator is logged in and then extract the super‑administrator’s session token, enabling an account takeover. The defect is a classic information‑exposure flaw (CWE‑200) that compounds poor permission controls (CWE‑269) and inadequate logging protections (CWE‑532).

Affected Systems

All WatchGuard Dimension installations that predate the release of v2.3.1 are vulnerable, as they retain the unredacted session‑token logging behavior described. WatchGuard recommends upgrading to v2.3.1 or newer to eliminate the fault.

Risk and Exploitability

The CVSS base score of 9.3 signals a critical risk. The EPSS score is currently not available, so the current exploitation probability is uncertain. The vulnerability is likely exploitable via the web UI diagnostic log, requiring only that an attacker possess low‑privileged Administrator rights and that a Super Administrator be actively logged in. It is not listed in CISA’s KEV catalog, but the severity and potential for account takeover warrant immediate remediation.

Generated by OpenCVE AI on August 28, 2026 at 07:32 UTC.

Remediation

Vendor Solution

Dimension 2.3.1


OpenCVE Recommended Actions

  • Apply the official fix by upgrading to WatchGuard Dimension 2.3.1 or later
  • Configure diagnostic logging to exclude or redact session identifiers, ensuring that sensitive tokens are not written to logs
  • Enforce least‑privilege by restricting Diagnostic Log access to Super Administrators only, revoking low‑privileged Administrators’ read rights

Generated by OpenCVE AI on August 28, 2026 at 07:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description WatchGuard Dimension records unredacted session identifiers for logged-in users in its web UI diagnostic log. A low-privileged Dimension Administrator can retrieve this log and extract a Super Administrator's session token while that administrator is logged in, enabling account takeover.
Title WatchGuard Dimension Session Hijack via Exposed Session Tokens in Diagnostic Logs
First Time appeared Watchguard
Watchguard dimension
Weaknesses CWE-200
CWE-269
CWE-532
CPEs cpe:2.3:a:watchguard:dimension:*:*:*:*:*:*:*:*
Vendors & Products Watchguard
Watchguard dimension
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:N/SA:N'}


Subscriptions

Watchguard Dimension
cve-icon MITRE

Status: PUBLISHED

Assigner: WatchGuard

Published:

Updated: 2026-08-27T23:26:30.875Z

Reserved: 2026-08-23T15:33:57.487Z

Link: CVE-2026-78174

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-28T02:16:22.950

Modified: 2026-08-28T02:16:22.950

Link: CVE-2026-78174

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T07:45:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-269

    Improper Privilege Management

  • CWE-532

    Insertion of Sensitive Information into Log File