CVE-2026-78618
A business logic flaw in WatchGuard Dimension allows an authenticated administrator to trigger multiple backend operations within a single l
CVSS
—
No CVSS
EPSS
—
KEV
—
Exploit Today
0
0-100
Published: Aug 28, 2026 · Last modified: Aug 28, 2026 · CWE-284 · CWE-841
Not enough EPSS history yet.
A business logic flaw in WatchGuard Dimension allows an authenticated administrator to trigger multiple backend operations within a single logical flow by sending a specially crafted request.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-78103——
——0WatchGuard Dimension provides a client-side lock/unlock UI control for management changes. The server-side configuration endpoint does not enforce this lock/unlock workflow state, allowing an authenticated administrator to submit configuration changes directly to the endpoint without first completing the UI unlock step. This allows an authenticated read-write administrator session to bypass the intended editing workflow and overwrite configuration changes being made by another concurrent administrator session.17hCVE-2026-64896——
——0Debug and Test Interface With Improper Access Control vulnerability in Johnson Controls T2000 allows Accessing Functionality Not Properly Constrained by ACLs.
This issue affects T2000: before 31.6.23hCVE-2026-815738.6 HIG37.8%
——11If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configuration command handler does not enforce network-
origin restrictions. Commands intended only for local or same-network clients can therefore be executed by
arbitrary remote peers. An attacker can read potentially sensitive configuration data and overwrite selected values
in Server.ini. This does include the hash of the credentials for the CodeMeter WebAdmin, enabling WebAdmin
takeover.1dCVE-2026-77034—14.8%
——4Joomla Extension - joomlaeventmanager.net - Unauthenticated article overwrite and force-publish in Joomla Event Manager < 5.0.1 - Any visitor holding their own session token can republish and overwrite an article associated with an event.1dCVE-2026-165694.3 MED3.1%
——1The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin through 0.4.62 does not check the user's capabilities before allowing a stock-update operation through one of its REST endpoints, allowing any authenticated user, such as a customer or subscriber, to change the stock quantity of arbitrary products.1dCVE-2026-753389.8 CRI6.5%
——2disconf (Distributed Configuration Management Platform) 2.6.36 is vulnerable to Incorrect Access Control. The config-fetching APIs /api/config/item, /api/config/file, /api/config/list and /api/config/simple/list are exposed without authentication. The LoginInterceptor explicitly whitelists these four paths, so any anonymous attacker can read every configuration item and configuration file managed by the config center.1d