CVE-2026-78174
moderateSession Token Leakage in WatchGuard Dimension Diagnostic Log Enables Admin Account Takeover
WatchGuard Dimension records the session identifiers of logged-in users, including Super Administrators, in unredacted form in its web UI diagnostic log. A low-privileged Dimension Administrator can retrieve that diagnostic log and, while a Super Administrator is logged in, extract the Super Administrator's live session token. With that token, the attacker can hijack the Super Administrator session and take over the account, gaining full administrative control of the Dimension management platform. Any organization running WatchGuard Dimension with both low-privileged administrators and Super Administrators using the web UI is affected. Exploitation has not been observed publicly: no proof-of-concept is known, the flaw is not in CISA KEV, and EPSS puts 30-day exploitation probability at just 0.3%.
What to do: Apply the WatchGuard Dimension security update per the vendor's advisory, since specific fixed version numbers are not provided in the available data. Until patched, restrict which Dimension Administrators can access the diagnostic log, review and minimize low-privileged admin accounts, and rotate Super Administrator sessions if unredacted tokens are present in logs. Note that Super Administrator accounts are only exposed while they are actively logged in, so limiting concurrent Super Administrator web sessions during the window reduces risk.
| WatchGuard Dimension | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
WatchGuard Dimension records unredacted session identifiers for logged-in users in its web UI diagnostic log. A low-privileged Dimension Administrator can retrieve this log and extract a Super Administrator's session token while that administrator is logged in, enabling account takeover.
- Weakness
- CWE-200, CWE-269, CWE-532
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.