Junglewise Threat Intelligence

CVE-2026-78500: WatchGuard Dimension blind SSRF in database test connection

CVE-2026-78500 · Severity: info · CVSS 5.1 · Published 2026-08-28

Technologies: Watchguard Dimension. Vendors: Watchguard.

Executive brief

WatchGuard Dimension is a security management platform used to administer firewalls and security appliances across a network. An authenticated privileged attacker can exploit a blind server-side request forgery (SSRF) vulnerability in the database test configuration feature to enumerate network services on adjacent systems, potentially revealing the presence of internal infrastructure and services that could be targeted for further attacks.

Technical details

The vulnerability is a blind SSRF (CWE-918) combined with observable timing discrepancies (CWE-208) in WatchGuard Dimension's database test connection feature. An authenticated user with administrative privileges can craft requests that cause the Dimension server to make requests to arbitrary adjacent network systems, and differences in response timing can reveal whether services are running on those systems. The attack requires authentication and network reachability to the Dimension server, but no user interaction. Attackers can achieve reconnaissance of adjacent network infrastructure. The vulnerability is fixed in Dimension version 2.3.1.

Affected products

  • WatchGuard Dimension 2.0 to 2.3.0

Timeline

  • 2026-08-27: disclosed
  • 2026-08-27: patched: Fix available in Dimension 2.3.1

References

Related threats