AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2026-26369

CRITICAL · CVSS 9.8 EPSS 0.64%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2026-02-15 · Last synced 2026-08-04

CyberRota Analysis

This is a critical severity vulnerability with a CVSS score of 9.8. See the original NVD description below for full technical details.

CVE
CVE-2026-26369
Severity
CRITICAL
CVSS
9.8
EPSS
0.64%

Original NVD Description

eNet SMART HOME server 2.2.1 and 2.3.1 contains a privilege escalation vulnerability due to insufficient authorization checks in the setUserGroup JSON-RPC method. A low-privileged user (UG_USER) can send a crafted POST request to /jsonrpc/management specifying their own username to elevate their account to the UG_ADMIN group, bypassing intended access controls and gaining administrative capabilities such as modifying device configurations, network settings, and other smart home system functions.

Related CVEs

Other vulnerabilities affecting the same vendor(s)