Login Vulnerability in WatchGuard Dimension Affects User Account Security
CVE-2026-78617

6.3MEDIUM

Key Information:

Vendor

Watchguard

Status
Vendor
CVE Published:
27 August 2026

Badges

👾 Exploit Exists

What is CVE-2026-78617?

The web login endpoint of WatchGuard Dimension lacks effective rate limiting and account lockout mechanisms by default. This oversight allows attackers to engage in automated password guessing attacks against user accounts. Although an optional account lockout feature can mitigate brute-force attempts after a specified number of failed logins, it is not enabled out-of-the-box. Therefore, users are urged to review their security settings and enable account lockout features to enhance protection against unauthorized access.

Affected Version(s)

Dimension 2.0 < 2.3.1

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Simone Paganessi (https://www.linkedin.com/in/simonepaganessi)
.