Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Enable Security

#30414of 57,632
9.1Total CVSS
Vulnerabilities · 1
PT-2026-107999
9.1
2026-10-08
Integrics · Enswitch · CVE-2026-107640
Integrics Enswitch 3.13 through 4.4 contains an authentication bypass vulnerability in /api/json/user/password/update/ that allows unauthenticated attackers to change account passwords by omitting the reset parameter. Attackers can target accounts with no pending reset, whose empty reset key matches the defaulted empty value, to take over administrator accounts after enumerating valid usernames.