Junglewise Threat Intelligence

CVE-2026-78495: WatchGuard Dimension server-side request forgery in Remote Backup Connection Test

CVE-2026-78495 · Severity: info · CVSS 5.3 · Published 2026-08-28

Technologies: Watchguard Dimension. Vendors: Watchguard.

Executive brief

WatchGuard Dimension is a backup and disaster recovery management platform used by organizations to protect critical business data. A server-side request forgery vulnerability in its Remote Backup Connection Test feature allows an authenticated administrator to probe and enumerate network services on adjacent systems, potentially revealing infrastructure details and exposed services that could be targeted for further attacks.

Technical details

This SSRF vulnerability (CWE-918) exists in WatchGuard Dimension's Remote Backup Connection Test configuration feature. An authenticated user with privileged administrative access can craft malicious requests that cause the Dimension server to make outbound connections to arbitrary internal network addresses and ports, allowing them to enumerate and probe adjacent network services. The vulnerability requires existing authentication and administrative privileges. A fix is available in Dimension version 2.3.1 and later. The vulnerability has not been observed in active exploitation as of the advisory publication date.

Affected products

  • WatchGuard Dimension >=2.0, <2.3.1

Timeline

  • 2026-08-27: disclosed
  • 2026-08-27: patched: Fixed in Dimension 2.3.1

References

Related threats