CVE-2026-78174 CRITICAL

CVE-2026-78174: WatchGuard Dimension Session Hijack via Exposed Session Tokens in Diagnostic Logs

Vendor Watchguard
Product Dimension
Weakness CWE-200 · Info exposure
Published August 27, 2026
Last update August 28, 2026

CVSS base score

9.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:N/SA:N

What the vulnerability does

01Description

WatchGuard Dimension records unredacted session identifiers for logged-in users in its web UI diagnostic log. A low-privileged Dimension Administrator can retrieve this log and extract a Super Administrator's session token while that administrator is logged in, enabling account takeover.

Key dates

02Disclosure timeline

August 27, 2026 CVE published
August 28, 2026 Record updated

Related vulnerabilities

04Related CVE