Description
WatchGuard Dimension's web login endpoint does not enforce effective rate-limiting or account lockout by default allowing a remote attacker to perform automated password guessing against user accounts. If the account lockout setting is enabled, brute-force attempts are blocked after a defined number of failed attempts, but this setting is not enabled by default.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Dimension 2.3.1
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://psirt.watchguard.com/CVE-2026-78617 |
|
History
Thu, 27 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WatchGuard Dimension's web login endpoint does not enforce effective rate-limiting or account lockout by default allowing a remote attacker to perform automated password guessing against user accounts. If the account lockout setting is enabled, brute-force attempts are blocked after a defined number of failed attempts, but this setting is not enabled by default. | |
| Title | WatchGuard Dimension Web UI Authentication Brute-Force Due to Missing Rate Limiting | |
| First Time appeared |
Watchguard
Watchguard dimension |
|
| Weaknesses | CWE-203 CWE-307 |
|
| CPEs | cpe:2.3:a:watchguard:dimension:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Watchguard
Watchguard dimension |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: WatchGuard
Published:
Updated: 2026-08-27T23:26:31.148Z
Reserved: 2026-08-24T21:19:03.651Z
Link: CVE-2026-78617
No data.
Status : Received
Published: 2026-08-28T02:16:24.450
Modified: 2026-08-28T02:16:24.450
Link: CVE-2026-78617
No data.
OpenCVE Enrichment
Updated: 2026-08-28T07:45:04Z