WatchGuard Dimension's web login endpoint does not enforce effective rate-limiting or account lockout by default allowing a remote attacker to perform automated password guessing against user accounts. If the account lockout setting is enabled, brute-force attempts are blocked after a defined number of failed attempts, but this setting is not enabled by default.
CVSS
No CVSS.
References
| Link | Resource |
|---|---|
| https://psirt.watchguard.com/CVE-2026-78617 |
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-28 02:16
Updated : 2026-08-28 20:19
NVD link : CVE-2026-78617
Mitre link : CVE-2026-78617
CVE.ORG link : CVE-2026-78617
JSON object : View
Products Affected
No product.
