Authorization Vulnerability in eNet SMART HOME Server by JUNG
CVE-2026-26367
7.1HIGH
What is CVE-2026-26367?
The eNet SMART HOME server versions 2.2.1 and 2.3.1 contain a flaw in its deleteUserAccount function within the JSON-RPC interface that allows any authenticated low-privileged user to delete other user accounts without the necessary permissions. This vulnerability arises from a lack of role-based access control, which permits standard users to craft requests that target and remove arbitrary accounts, excluding the built-in admin account. This can lead to unauthorized modifications and may compromise the integrity and security of user data and overall access management.
Affected Version(s)
eNet SMART HOME server 2.3.1 (46841)
eNet SMART HOME server 2.2.1 (46056)
References
CVSS V4
Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
LiquidWorm as Gjoko Krstic of Zero Science Lab
