Executive brief
WatchGuard Dimension is a security management and analytics platform used by organizations to monitor and control network activity. This vulnerability allows an attacker to change an administrator's passphrase by tricking an authenticated administrator into visiting a malicious webpage, potentially leading to unauthorized administrative access and compromise of the entire security infrastructure.
Technical details
This is a cross-site request forgery (CSRF) vulnerability in WatchGuard Dimension's Web UI that affects the administrator passphrase change endpoint (CWE-352). The vulnerability arises from insufficient CSRF token validation on the passphrase change action. An attacker can craft a malicious link or webpage that, when visited by an authenticated global administrator, issues a request to change the administrator's passphrase without the administrator's knowledge or consent. The attack requires that the target administrator be actively authenticated to the Dimension Web UI. Successful exploitation grants the attacker full administrative access to the Dimension platform. The vulnerability is fixed in Dimension version 2.3.1 and later.
Affected products
- WatchGuard Dimension >=2.0, <2.3.1
Timeline
- 2026-08-27: disclosed
- 2026-08-27: patched: Dimension 2.3.1