Executive brief
WatchGuard Dimension is an administrative management and monitoring platform used by organizations to centrally control and oversee network security appliances. A business logic flaw allows authenticated administrators to trigger unintended backend operations by crafting a malicious request, potentially bypassing security controls or performing unauthorized actions within the system.
Technical details
This vulnerability is a business logic flaw (CWE-284 Improper Access Control, CWE-841 Improper Enforcement of Behavioral Workflow) in WatchGuard Dimension that permits an authenticated administrator to chain multiple backend object operations within a single logical flow by sending a specially crafted request. The vulnerability requires valid administrator authentication and network access to the Dimension interface. An attacker with admin credentials can exploit this to bypass normal workflow restrictions and perform unauthorized or cascading operations on backend objects. The vulnerability affects Dimension versions prior to 2.3.1; patched versions 2.3.1 and later are not affected.
Affected products
- WatchGuard Dimension < 2.3.1
Timeline
- 2026-08-27: disclosed
- 2026-08-27: patched: Dimension 2.3.1