CVE-2026-78174 is an improper sensitive-data logging vulnerability in WatchGuard Dimension. The web UI diagnostic log records unredacted session identifiers for authenticated users. A Dimension Administrator with lower privileges can retrieve these logs and extract the active session token of a Super Administrator, allowing the lower-privileged user to impersonate that administrator. The issue is also associated with exposure of sensitive information and improper privilege management.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Critical session-hijacking vulnerability in WatchGuard Dimension caused by exposed session tokens in diagnostic logs, enabling a low-privileged administrator to take over a Super Administrator session.
A WatchGuard Dimension web UI diagnostic-log exposure that records unredacted authenticated session identifiers. A low-privileged Dimension Administrator can obtain a concurrently logged-in Super Administrator's session token from the log and hijack that account.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.