Description
A server-side request forgery (SSRF) vulnerability WatchGuard Dimension FTP Server Test configuration allows an authenticated privileged attacker to enumerate exposed network services on adjacent network systems.
Published: 2026-08-27
Score: 5.1 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

WatchGuard Dimension allows an authenticated privileged user to send a test FTP connection request that the system forwards to arbitrary network destinations. Because the request is made from the server itself, the victim can probe for any service exposed on adjacent internal hosts. This can reveal hostnames, open ports, and potentially additional vulnerabilities. The weakness is a classic Server Side Request Forgery (CWE‑918). The impact is limited to the information discovered; there is no direct code execution or data modification asserted by the description.

Affected Systems

The affected product is WatchGuard Dimension. No specific version is listed in the CVE data, but the vendor’s official fix is release 2.3.1. Users should verify that their deployment is on or earlier than that version and plan to apply the patch if applicable.

Risk and Exploitability

The CVSS score of 5.1 indicates a moderate risk. EPSS is not available, but the vulnerability is not listed in CISA’s KEV catalog, suggesting no mass exploitation is documented. The attack requires authenticated privileged access, meaning that an attacker must have user credentials with the necessary rights. Once authenticated, the attacker can enumerate services on adjacent networks, which can aid in deeper network reconnaissance for future attacks.

Generated by OpenCVE AI on August 28, 2026 at 07:50 UTC.

Remediation

Vendor Solution

Dimension 2.3.1


OpenCVE Recommended Actions

  • Update WatchGuard Dimension to 2.3.1 or later to address the SSRF flaw.
  • Restrict privileged user access to the FTP Server Test Connection feature; revoke or limit rights for users who do not require it.
  • Configure or disable the test connection endpoint to only allow connections to localhost or approved IP ranges, or apply network segmentation to prevent internal enumeration.

Generated by OpenCVE AI on August 28, 2026 at 07:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description A server-side request forgery (SSRF) vulnerability WatchGuard Dimension FTP Server Test configuration allows an authenticated privileged attacker to enumerate exposed network services on adjacent network systems.
Title Dimension SSRF via FTP Server Test Connection
First Time appeared Watchguard
Watchguard dimension
Weaknesses CWE-918
CPEs cpe:2.3:a:watchguard:dimension:*:*:*:*:*:*:*:*
Vendors & Products Watchguard
Watchguard dimension
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N'}


Subscriptions

Watchguard Dimension
cve-icon MITRE

Status: PUBLISHED

Assigner: WatchGuard

Published:

Updated: 2026-08-27T23:26:30.962Z

Reserved: 2026-08-24T17:20:04.411Z

Link: CVE-2026-78499

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-28T02:16:23.443

Modified: 2026-08-28T02:16:23.443

Link: CVE-2026-78499

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T08:00:13Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)