PT-2026-107999 · Integrics · Enswitch

·

CVE-2026-107640

·

Published

2026-10-08

·

Updated

2026-10-08

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Integrics Enswitch 3.13 through 4.4 contains an authentication bypass vulnerability in /api/json/user/password/update/ that allows unauthenticated attackers to change account passwords by omitting the reset parameter. Attackers can target accounts with no pending reset, whose empty reset key matches the defaulted empty value, to take over administrator accounts after enumerating valid usernames.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-107640

Affected Products

Enswitch