{"id":"CVE-2026-78610","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-78610","summary":"WatchGuard Dimension's Web UI exposes an administrator passphrase change action that lacks CSRF protection. An attacker who can induce an authenticated global administrator's browser…","details":"WatchGuard Dimension's Web UI exposes an administrator passphrase change action that lacks CSRF protection. An attacker who can induce an authenticated global administrator's browser to visit a crafted link or page can change that administrator's passphrase to an attacker-chosen value without the administrator's consent.","published":"2026-08-28T02:16:23.687","modified":"2026-08-28T02:16:23.687","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://psirt.watchguard.com/CVE-2026-78610"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-28T02:16:23.687"}}