Description
A business logic flaw in WatchGuard Dimension allows an authenticated administrator to trigger multiple backend operations within a single logical flow by sending a specially crafted request.
Published: 2026-08-27
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A business logic flaw in WatchGuard Dimension enables an authenticated administrator to trigger a series of backend operations in a single request. The flaw permits execution of multiple privileged actions that the administrator would normally need to initiate separately, effectively giving the attacker the ability to perform unintended or potentially harmful operations within the system. The associated weaknesses are improper access control (CWE-284) and improper authorization (CWE-841).

Affected Systems

The vulnerability affects WatchGuard Dimension installations that have not yet applied the official update, which addresses the flaw in version 2.3.1. Specific affected versions are not listed in the advisory, but any release prior to the patch is potentially vulnerable.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate severity, and the vulnerability is not currently listed in the CISA KEV catalog. While no EPSS score is available, the requirement for administrator authentication suggests that the attacker must first compromise or legitimately assume an admin role. The flaw could be exploited to run arbitrary backend processes, potentially compromising data integrity or availability, but the high privilege requirement limits the scope to systems where an attacker can gain administrative access.

Generated by OpenCVE AI on August 28, 2026 at 08:13 UTC.

Remediation

Vendor Solution

Dimension 2.3.1


OpenCVE Recommended Actions

  • Apply the official update to reach Dimension 2.3.1
  • Revoke or replace any administrator credentials that may have been used during exploitation
  • Perform a focused review of backend operation permissions to ensure only authorised users can trigger privileged actions

Generated by OpenCVE AI on August 28, 2026 at 08:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description A business logic flaw in WatchGuard Dimension allows an authenticated administrator to trigger multiple backend operations within a single logical flow by sending a specially crafted request.
Title Dimension Business Logic Flaw Allows Chained Backend Object Operations
First Time appeared Watchguard
Watchguard dimension
Weaknesses CWE-284
CWE-841
CPEs cpe:2.3:a:watchguard:dimension:*:*:*:*:*:*:*:*
Vendors & Products Watchguard
Watchguard dimension
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N'}


Subscriptions

Watchguard Dimension
cve-icon MITRE

Status: PUBLISHED

Assigner: WatchGuard

Published:

Updated: 2026-08-27T23:26:30.669Z

Reserved: 2026-08-24T21:19:12.822Z

Link: CVE-2026-78618

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-28T02:16:24.580

Modified: 2026-08-28T02:16:24.580

Link: CVE-2026-78618

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T08:15:06Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-841

    Improper Enforcement of Behavioral Workflow