Vulnerability Description
WatchGuard Dimension records unredacted session identifiers for logged-in users in its web UI diagnostic log. A low-privileged Dimension Administrator can retrieve this log and extract a Super Administrator's session token while that administrator is logged in, enabling account takeover.
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-78174?
CVE-2026-78174 is a documented vulnerability. WatchGuard Dimension records unredacted session identifiers for logged-in users in its web UI diagnostic log. A low-privileged Dimension Administrator can retrieve this log and extract a Super Adminis...
How severe is CVE-2026-78174?
CVSS scoring is not yet available for CVE-2026-78174. Check NVD for updates.
Is there a patch for CVE-2026-78174?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.