Description
A server-side request forgery (SSRF) vulnerability WatchGuard Dimension Email Server Test configuration allows an authenticated privileged attacker to enumerate exposed network services on adjacent network systems.
Published: 2026-08-27
Score: 5.1 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A server‑side request forgery flaw exists in the WatchGuard Dimension Email Server Test configuration. The vulnerability allows an authenticated privileged user to craft requests that force the device to reach arbitrary internal URLs, enabling enumeration of exposed network services on adjacent hosts. The impact is the discovery of internal services, which can facilitate further attacks by revealing potential attack vectors within the internal network.

Affected Systems

The affected product is WatchGuard Dimension, with releases prior to Version 2.3.1 presumably impacted. No specific sub‑versions are listed, but the vendor’s advisory recommends applying Version 2.3.1 to remediate.

Risk and Exploitability

The CVSS score of 5.1 indicates a moderate risk. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no currently known widespread exploitation. Exploitation requires authenticated privileged access to the Dimension appliance, so limiting privileged accounts and enforcing strong authentication mitigates risk. An attacker can use the SSRF vector to probe internal network services but cannot gain execution or arbitrary code unless other flaws are present.

Generated by OpenCVE AI on August 28, 2026 at 07:28 UTC.

Remediation

Vendor Solution

Dimension 2.3.1


OpenCVE Recommended Actions

  • Upgrade Dimension to Version 2.3.1
  • Restrict privileged user accounts to the minimum required permissions
  • Disable the Email Server Test feature if it is not needed for normal operations

Generated by OpenCVE AI on August 28, 2026 at 07:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description A server-side request forgery (SSRF) vulnerability WatchGuard Dimension Email Server Test configuration allows an authenticated privileged attacker to enumerate exposed network services on adjacent network systems.
Title Dimension Server-Side Request Forgery via Email Server Test Settings
First Time appeared Watchguard
Watchguard dimension
Weaknesses CWE-918
CPEs cpe:2.3:a:watchguard:dimension:*:*:*:*:*:*:*:*
Vendors & Products Watchguard
Watchguard dimension
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N'}


Subscriptions

Watchguard Dimension
cve-icon MITRE

Status: PUBLISHED

Assigner: WatchGuard

Published:

Updated: 2026-08-27T23:26:31.719Z

Reserved: 2026-08-24T17:19:37.348Z

Link: CVE-2026-78498

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-28T02:16:23.317

Modified: 2026-08-28T02:16:23.317

Link: CVE-2026-78498

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T07:30:07Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)