CVE-2026-78103 MEDIUM

CVE-2026-78103: Dimension Log Server Configuration Lock Bypass Vulnerability

Vendor Watchguard
Product Dimension
Weakness CWE-841
Published August 27, 2026
Last update August 28, 2026

CVSS base score

5.1/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

WatchGuard Dimension provides a client-side lock/unlock UI control for management changes. The server-side configuration endpoint does not enforce this lock/unlock workflow state, allowing an authenticated administrator to submit configuration changes directly to the endpoint without first completing the UI unlock step. This allows an authenticated read-write administrator session to bypass the intended editing workflow and overwrite configuration changes being made by another concurrent administrator session.

Key dates

02Disclosure timeline

August 27, 2026 CVE published
August 28, 2026 Record updated