CVE-2026-78610

WatchGuard Dimension's Web UI exposes an administrator passphrase change action that lacks CSRF protection. An attacker who can induce an authenticated global administrator's browser to visit a crafted link or page can change that administrator's passphrase to an attacker-chosen value without the administrator's consent.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-08-28 02:16

Updated : 2026-08-28 20:19


NVD link : CVE-2026-78610

Mitre link : CVE-2026-78610

CVE.ORG link : CVE-2026-78610


JSON object : View

Products Affected

No product.

CWE
CWE-352

Cross-Site Request Forgery (CSRF)