SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-78103

MEDIUM · CVSS 5.1 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

WatchGuard Dimension's server-side configuration endpoint fails to enforce the client-side lock/unlock workflow, enabling authenticated administrators to bypass the intended editing process. This vulnerability allows one administrator to overwrite configuration changes made by another concurrent session, potentially leading to misconfigurations or unauthorized alterations. Organizations using WatchGuard Dimension should prioritize addressing this issue to maintain the integrity of their configuration management processes.

CVE
CVE-2026-78103
Severity
MEDIUM
CVSS
5.1
EPSS
0.29%

Original NVD Description

WatchGuard Dimension provides a client-side lock/unlock UI control for management changes. The server-side configuration endpoint does not enforce this lock/unlock workflow state, allowing an authenticated administrator to submit configuration changes directly to the endpoint without first completing the UI unlock step. This allows an authenticated read-write administrator session to bypass the intended editing workflow and overwrite configuration changes being made by another concurrent administrator session.