CVE-2026-78174

WatchGuard Dimension records unredacted session identifiers for logged-in users in its web UI diagnostic log. A low-privileged Dimension Administrator can retrieve this log and extract a Super Administrator's session token while that administrator is logged in, enabling account takeover.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-08-28 02:16

Updated : 2026-08-28 20:19


NVD link : CVE-2026-78174

Mitre link : CVE-2026-78174

CVE.ORG link : CVE-2026-78174


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-269

Improper Privilege Management

CWE-532

Insertion of Sensitive Information into Log File