CVE-2026-78174 – Watchguard Dimension
CVSS 9.3
CRITICAL
Critical - Same Day Deployment
“A leaked administrator session token can turn limited access into full control.”
WatchGuard fixed a critical privilege-escalation flaw in Dimension that exposed unredacted session identifiers in diagnostic logs. CVE-2026-78174 allows a low-privileged Dimension Administrator to retrieve a logged-in Super Administrator’s session token and take over that account. The CVSS score is 9.3, which is Critical severity.
The issue affects Dimension versions 2.0 through versions before 2.3.1. Dimension 2.3.1 contains the fix.
Key Details
- CWE Classification
- CWE-200
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.