Authorization Vulnerability in eNet SMART HOME Server by JUNG
CVE-2026-26367

7.1HIGH

Key Information:

Vendor

Jung

Vendor
CVE Published:
15 February 2026

What is CVE-2026-26367?

The eNet SMART HOME server versions 2.2.1 and 2.3.1 contain a flaw in its deleteUserAccount function within the JSON-RPC interface that allows any authenticated low-privileged user to delete other user accounts without the necessary permissions. This vulnerability arises from a lack of role-based access control, which permits standard users to craft requests that target and remove arbitrary accounts, excluding the built-in admin account. This can lead to unauthorized modifications and may compromise the integrity and security of user data and overall access management.

Affected Version(s)

eNet SMART HOME server 2.3.1 (46841)

eNet SMART HOME server 2.2.1 (46056)

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

LiquidWorm as Gjoko Krstic of Zero Science Lab
.