Executive brief
WatchGuard Dimension is a centralized management platform for security appliances. The platform stores unredacted session identifiers (authentication tokens) in diagnostic logs that lower-privileged administrators can access. An attacker with basic admin rights can extract a Super Administrator's active session token and use it to impersonate that account, gaining full control of the system without needing to know the administrator's password.
Technical details
The vulnerability is an information disclosure and privilege escalation issue (CWE-200, CWE-269, CWE-532) where Dimension's web UI diagnostic logs contain unredacted session identifiers for all authenticated users. An attacker with Dimension Administrator privileges (but not Super Administrator) can access these diagnostic logs through the web interface and extract active session tokens of Super Administrators. With a valid session token, the attacker can perform session hijacking (CAPEC-593) to gain unauthorized Super Administrator access without needing to compromise credentials. The vulnerability requires the attacker to have valid administrative credentials and for a Super Administrator to have an active logged-in session. The fix is to upgrade to Dimension 2.3.1 or later, which redacts session tokens from diagnostic logs.
Affected products
- WatchGuard Dimension 2.0 to 2.3.0
Timeline
- 2026-08-27: disclosed
- 2026-08-27: patched: Dimension 2.3.1 released