CVE-2026-26367Disclosure(jung-group / enet_smart_home)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

eNet SMART HOME server 2.2.1 and 2.3.1 contains a missing authorization vulnerability in the deleteUserAccount JSON-RPC method that permits any authenticated low-privileged user (UG_USER) to delete arbitrary user accounts, except for the built-in admin account. The application does not enforce role-based access control on this function, allowing a standard user to submit a crafted POST request to /jsonrpc/management specifying another username to have that account removed without elevated permissions or additional confirmation.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • enet_smart_home

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-02-15); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
enet_smart_home

2 versions affected across 1 product

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-15: 2Mentions · 2026-02-16: 1Technical Details · 2026-02-15: 2Technical Details · 2026-02-16: 102-1502-16
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-152
Disclosure2
2026-02-161
Disclosure1
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-26367 Unauthorized User Account Deletion in eNet SMART HOME Server 2.2.1 and 2.3.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-26367

    Post summary

    The post discloses CVE-2026-26367, detailing an unauthorized user account deletion vulnerability in specific eNet SMART HOME Server versions, with no evidence of PoC, exploit, patch, or active exploitation.

    0002040
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26367 eNet SMART HOME server 2.2.1 and 2.3.1 contains a missing authorization vulnerability in the deleteUserAccount JSON-RPC method that permits any authenticated low-priv… https://www.cve.org/CVERecord?id=CVE-2026-26367

    Post summary

    CVE-2026-26367 reveals a missing authorization flaw in eNet SMART HOME server’s deleteUserAccount JSON‑RPC method, enabling authenticated low‑privileged users to delete accounts.

    00011882
    56.4K followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Disclosure

    🚨 HIGH severity: JUNG eNet SMART HOME server (2.2.1 & 2.3.1) flaw lets any user delete accounts via missing authorization. Limit access & monitor accounts ASAP! https://radar.offseq.com/threat/cve-2026-26367-missing-authorization-in-jung-enet--173718f4 #OffSeq #SmartHome #Vuln... https://t.co/GRLRx6EU0w

    Post summary

    The tweet announces a high‑severity missing‑authorization flaw in JUNG eNet SMART HOME server that lets users delete accounts, urging administrators to restrict access and monitor accounts.

    0001043
    265 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appjung-groupenet_smart_home2.2.1--
Appjung-groupenet_smart_home2.3.1--

Explore more