CVE-2026-78174EPSS p34.8%
CVE-2026-78174CVE-2026-78174
Description
WatchGuard Dimension records unredacted session identifiers for logged-in users in its web UI diagnostic log. A low-privileged Dimension Administrator can retrieve this log and extract a Super Administrator's session token while that administrator is logged in, enabling account takeover.
Scoring
| EPSS | 0.43% probability of exploitation · percentile 34.8% · 2026-10-05T12:00:23Z |
| Last modified | 2026-08-28 |