Critical severity9.1NVD Advisory· Published Oct 8, 2026· Updated Oct 8, 2026
CVE-2026-107640
CVE-2026-107640
Description
Integrics Enswitch 3.13 through 4.4 contains an authentication bypass vulnerability in /api/json/user/password/update/ that allows unauthenticated attackers to change account passwords by omitting the reset parameter. Attackers can target accounts with no pending reset, whose empty reset_key matches the defaulted empty value, to take over administrator accounts after enumerating valid usernames.
Affected products
1Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.