CVE-2026-78610
largeCSRF in WatchGuard Dimension Web UI enables global administrator passphrase hijacking
CVE-2026-78610 is a cross-site request forgery flaw (CWE-352) in the Web UI of WatchGuard Dimension: the administrator passphrase-change action has no CSRF protection. An attacker who can induce an authenticated global administrator's browser to visit a crafted link or page can silently submit that action. This lets the attacker set the global administrator's passphrase to a value of their choosing without the administrator's consent, effectively taking control of the Dimension management account. Organizations running WatchGuard Dimension and administering it through the Web UI are affected. No exploitation is currently known: there is no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS puts 30-day exploitation probability at about 0.2%.
What to do: Watch for the WatchGuard advisory and apply the vendor's fixed Dimension release as soon as it is identified, since fixed versions are not stated in the available data. In the meantime, restrict access to the Dimension Web UI to trusted management networks or VPN, avoid clicking unsolicited links while logged in as a global administrator, and review logs for unexpected global-admin passphrase changes.
| WatchGuard Dimension | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
WatchGuard Dimension's Web UI exposes an administrator passphrase change action that lacks CSRF protection. An attacker who can induce an authenticated global administrator's browser to visit a crafted link or page can change that administrator's passphrase to an attacker-chosen value without the administrator's consent.
- Weakness
- CWE-352
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.