Description
WatchGuard Dimension's Web UI exposes an administrator passphrase change action that lacks CSRF protection. An attacker who can induce an authenticated global administrator's browser to visit a crafted link or page can change that administrator's passphrase to an attacker-chosen value without the administrator's consent.
Published: 2026-08-27
Score: 8.4 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability allows an attacker to alter an authenticated global administrator's passphrase through a crafted link or page, without the administrator’s consent. The lack of CSRF protection enables the attacker to assume control of the administrator account or lock the legitimate administrator out, leading to potential full system compromise.

Affected Systems

WatchGuard Dimension web UI. All versions prior to the released patch are affected. The official fix is available as Dimension 2.3.1, which implements CSRF protection on the passphrase change endpoint.

Risk and Exploitability

The CVSS score of 8.4 classifies this issue as high severity. Although a current EPSS value is not published, the lack of a CISA KEV listing does not reduce its potential impact. The exploitation requires only that an attacker host a malicious page and persuade a legitimate administrator to click or visit that page while logged in. The successful attack results in the attacker choosing the new passphrase, effectively granting full administrative control or denying the legitimate administrator access.

Generated by OpenCVE AI on August 28, 2026 at 07:49 UTC.

Remediation

Vendor Solution

Dimension 2.3.1


OpenCVE Recommended Actions

  • Upgrade to WatchGuard Dimension 2.3.1 or later to apply the CSRF protection fix.
  • Enforce strong, unique passphrases for all administrator accounts and monitor password change events for anomalies.
  • Implement additional monitoring of administrative login sessions to detect suspicious activity and potential credential compromise.

Generated by OpenCVE AI on August 28, 2026 at 07:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description WatchGuard Dimension's Web UI exposes an administrator passphrase change action that lacks CSRF protection. An attacker who can induce an authenticated global administrator's browser to visit a crafted link or page can change that administrator's passphrase to an attacker-chosen value without the administrator's consent.
Title Dimension CSRF Vulnerability in Administrator Passphrase Change Endpoint
First Time appeared Watchguard
Watchguard dimension
Weaknesses CWE-352
CPEs cpe:2.3:a:watchguard:dimension:*:*:*:*:*:*:*:*
Vendors & Products Watchguard
Watchguard dimension
References
Metrics cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Watchguard Dimension
cve-icon MITRE

Status: PUBLISHED

Assigner: WatchGuard

Published:

Updated: 2026-08-27T23:26:31.006Z

Reserved: 2026-08-24T21:18:14.096Z

Link: CVE-2026-78610

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-28T02:16:23.687

Modified: 2026-08-28T02:16:23.687

Link: CVE-2026-78610

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T08:00:13Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)