Integrics · Enswitch · CVE-2026-107640
Integrics Enswitch 3.13 through 4.4 contains an authentication bypass vulnerability in /api/json/user/password/update/ that allows unauthenticated attackers to change account passwords by omitting the reset parameter. Attackers can target accounts with no pending reset, whose empty reset key matches the defaulted empty value, to take over administrator accounts after enumerating valid usernames.