ZeroHour

CVE-2026-78174

moderate

Session Token Leakage in WatchGuard Dimension Diagnostic Log Enables Admin Account Takeover

CVSS 4.0
9.3 critical
EPSS
<1%p28
Published
()
Modified
AI analysis

WatchGuard Dimension records the session identifiers of logged-in users, including Super Administrators, in unredacted form in its web UI diagnostic log. A low-privileged Dimension Administrator can retrieve that diagnostic log and, while a Super Administrator is logged in, extract the Super Administrator's live session token. With that token, the attacker can hijack the Super Administrator session and take over the account, gaining full administrative control of the Dimension management platform. Any organization running WatchGuard Dimension with both low-privileged administrators and Super Administrators using the web UI is affected. Exploitation has not been observed publicly: no proof-of-concept is known, the flaw is not in CISA KEV, and EPSS puts 30-day exploitation probability at just 0.3%.

What to do: Apply the WatchGuard Dimension security update per the vendor's advisory, since specific fixed version numbers are not provided in the available data. Until patched, restrict which Dimension Administrators can access the diagnostic log, review and minimize low-privileged admin accounts, and rotate Super Administrator sessions if unredacted tokens are present in logs. Note that Super Administrator accounts are only exposed while they are actively logged in, so limiting concurrent Super Administrator web sessions during the window reduces risk.

Affected
WatchGuard Dimension
Estimated exposure
moderatelikely thousands of Dimension deployments (one management server per organization/MSP managing WatchGuard Fireboxes); exact and internet-exposed counts unknown — Dimension is a dedicated on-premises or virtual management server typically deployed once per organization or managed-service provider rather than per device, so the installed base is far smaller than WatchGuard's firewall fleet, and no…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

WatchGuard Dimension records unredacted session identifiers for logged-in users in its web UI diagnostic log. A low-privileged Dimension Administrator can retrieve this log and extract a Super Administrator's session token while that administrator is logged in, enabling account takeover.

Weakness
CWE-200, CWE-269, CWE-532
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.