CVE-2026-78103

WatchGuard Dimension provides a client-side lock/unlock UI control for management changes. The server-side configuration endpoint does not enforce this lock/unlock workflow state, allowing an authenticated administrator to submit configuration changes directly to the endpoint without first completing the UI unlock step. This allows an authenticated read-write administrator session to bypass the intended editing workflow and overwrite configuration changes being made by another concurrent administrator session.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-08-28 02:16

Updated : 2026-08-28 20:19


NVD link : CVE-2026-78103

Mitre link : CVE-2026-78103

CVE.ORG link : CVE-2026-78103


JSON object : View

Products Affected

No product.

CWE
CWE-841

Improper Enforcement of Behavioral Workflow