Missing Authorization Vulnerability in JUNG eNet SMART HOME Server
CVE-2026-26368

8.7HIGH

Key Information:

Vendor

Jung

Vendor
CVE Published:
15 February 2026

What is CVE-2026-26368?

The JUNG eNet SMART HOME server versions 2.2.1 and 2.3.1 contain a missing authorization vulnerability within the resetUserPassword JSON-RPC method. This security flaw enables any authenticated user with low privileges to reset the passwords of any accounts, including those of administrators, without needing the current password or required permissions. By crafting specific JSON-RPC requests to the /jsonrpc/management endpoint, attackers can compromise existing credentials, leading to unauthorized access and potential long-term elevation of privileges, rendering the system vulnerable to exploit.

Affected Version(s)

eNet SMART HOME server 2.3.1 (46841)

eNet SMART HOME server 2.2.1 (46056)

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

LiquidWorm as Gjoko Krstic of Zero Science Lab
.