OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-86553

HIGH · CVSS 8.8 EPSS 0.52%

Source: NVD + CISA KEV + EPSS · Published 2026-09-20 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

The SmartLife app is vulnerable due to its dynamic generation of authentication parameters, which can be exploited by attackers to access the backend interface and retrieve real account IDs linked to registered email addresses. This allows attackers to spoof authentication information and reset passwords for targeted accounts, potentially compromising user data and privacy. Organizations using the SmartLife app should prioritize addressing this vulnerability to protect their users from unauthorized account access.

CVE
CVE-2026-86553
Severity
HIGH
CVSS
8.8
EPSS
0.52%

Original NVD Description

SmartLife app dynamically generates fresh SmartLife application authentication parameters inside its runtime process. Using the acquired SmartLife application authentication parameters, an attacker can directly call the backend interface /account/verify.serv to obtain the real account ID corresponding to a registered email address. By spoofing the application authentication information together with the target account ID, the attacker can reset the password of the target account.