Vulnerability Description
WatchGuard Dimension's Web UI exposes an administrator passphrase change action that lacks CSRF protection. An attacker who can induce an authenticated global administrator's browser to visit a crafted link or page can change that administrator's passphrase to an attacker-chosen value without the administrator's consent.
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-78610?
CVE-2026-78610 is a documented vulnerability. WatchGuard Dimension's Web UI exposes an administrator passphrase change action that lacks CSRF protection. An attacker who can induce an authenticated global administrator's browser to visit a crafte...
How severe is CVE-2026-78610?
CVSS scoring is not yet available for CVE-2026-78610. Check NVD for updates.
Is there a patch for CVE-2026-78610?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.