SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-78617

MEDIUM · CVSS 6.3 EPSS 0.32%

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

WatchGuard Dimension's web login endpoint is vulnerable due to a lack of default rate-limiting and account lockout mechanisms, enabling remote attackers to execute automated password guessing attacks. If the account lockout feature is activated, it can mitigate brute-force attempts, but this protection is not enabled by default. Organizations using WatchGuard Dimension should prioritize addressing this vulnerability to safeguard user accounts against unauthorized access.

CVE
CVE-2026-78617
Severity
MEDIUM
CVSS
6.3
EPSS
0.32%

Original NVD Description

WatchGuard Dimension's web login endpoint does not enforce effective rate-limiting or account lockout by default allowing a remote attacker to perform automated password guessing against user accounts. If the account lockout setting is enabled, brute-force attempts are blocked after a defined number of failed attempts, but this setting is not enabled by default.