Server-Side Request Forgery Vulnerability in WatchGuard Dimension
CVE-2026-78495

5.3MEDIUM

Key Information:

Vendor

Watchguard

Status
Vendor
CVE Published:
27 August 2026

Badges

👾 Exploit Exists

What is CVE-2026-78495?

A server-side request forgery vulnerability in WatchGuard Dimension's Remote Backup Connection Test configuration permits an authenticated privileged attacker to systematically discover and enumerate exposed network services on connected systems within the same network. This vulnerability could potentially lead to unauthorized access and manipulation of sensitive information across the network, making it crucial for organizations to implement necessary patches and security measures to safeguard their infrastructure.

Affected Version(s)

Dimension 2.0 < 2.3.1

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Simone Paganessi (https://www.linkedin.com/in/simonepaganessi)
.