Integrics Enswitch 3.13 through 4.4 contains an authentication bypass vulnerability in /api/json/user/password/update/ that allows unauthenticated attackers to change account passwords by omitting the reset parameter. Attackers can target accounts with no pending reset, whose empty reset_key matches the defaulted empty value, to take over administrator accounts after enumerating valid usernames.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 08 Oct 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Integrics Enswitch 3.13 through 4.4 contains an authentication bypass vulnerability in /api/json/user/password/update/ that allows unauthenticated attackers to change account passwords by omitting the reset parameter. Attackers can target accounts with no pending reset, whose empty reset_key matches the defaulted empty value, to take over administrator accounts after enumerating valid usernames. | |
| Title | Integrics Enswitch 3.13 through 4.4 Authentication Bypass via Password Reset API | |
| Weaknesses | CWE-640 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-08T16:04:49.173Z
Reserved: 2026-10-08T14:06:01.084Z
Link: CVE-2026-107640
No data.
Status : Received
Published: 2026-10-08T15:17:47.343
Modified: 2026-10-08T16:17:04.763
Link: CVE-2026-107640
No data.
OpenCVE Enrichment
Updated: 2026-10-08T16:00:06Z
Weaknesses