CVE-2026-26369Disclosure(jung-group / enet_smart_home)

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch jung-group enet_smart_home systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

eNet SMART HOME server 2.2.1 and 2.3.1 contains a privilege escalation vulnerability due to insufficient authorization checks in the setUserGroup JSON-RPC method. A low-privileged user (UG_USER) can send a crafted POST request to /jsonrpc/management specifying their own username to elevate their account to the UG_ADMIN group, bypassing intended access controls and gaining administrative capabilities such as modifying device configurations, network settings, and other smart home system functions.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • enet_smart_home

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 8 signals
  • Disclosure: 7 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 4 mentions (2026-02-15); latest day: 1
  • 8 total mentions across 3 days

Affected systems

Vendors
Products
enet_smart_home

2 versions affected across 1 product

Deep dive

Activity timeline8 mentions / 3d
01234Mentions · 2026-02-15: 4Mentions · 2026-02-16: 3Mentions · 2026-02-20: 1Patch / Workaround · 2026-02-16: 1Technical Details · 2026-02-15: 4Technical Details · 2026-02-16: 3Technical Details · 2026-02-20: 102-1502-1602-20
Signal classification2 categories
Disclosure
787.5%
General
112.5%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-02-154
Disclosure3General1
2026-02-163
Disclosure3
2026-02-201
Disclosure1
Full discourse8 posts
  • NerdieNews@NewsNerdie
    Disclosure

    Today's Top Cybersecurity News – February 16, 2026 1. Multiple Stack Buffer Overflow Vulnerabilities in Bosch Infotainment ECU Bluetooth Stack Three distinct stack-based buffer overflow vulnerabilities (CVE-2025-32059, CVE-2025-32061, CVE-2025-32062) have been identified in the Bluetooth stack developed by Alps Alpine for Bosch Infotainment ECUs. These flaws allow remote attackers to execute arbitrary code via malformed packets on the L2CAP channel, posing significant risks to vehicle infotainment system security. Sources: Cvefeed https://cvefeed.io/vuln/detail/CVE-2025-32062 2. Critical Privilege Escalation and Account Takeover Vulnerabilities in JUNG eNet SMART HOME Server Multiple critical vulnerabilities in JUNG eNet SMART HOME server versions 2.2.1 and 2.3.1 allow low-privileged users to escalate privileges, reset passwords of admin accounts without authorization, and exploit default credentials to gain administrative access. These flaws expose smart home environments to unauthorized control and potential compromise. Sources: Cvefeed https://cvefeed.io/vuln/detail/CVE-2026-26369 3. Suspected Russian APT Deploys CANFAIL Malware Targeting Ukrainian Critical Sectors A newly identified Russia-linked APT group has deployed CANFAIL malware against Ukrainian defense, government, and energy organizations, posing significant risks to critical infrastructure. The attacks highlight ongoing geopolitical cyber threats and potential disruptions to national security and energy operations. Sources: Feedburner, Securityaffairs https://securityaffairs.com/187976/hacking/suspected-russian-hackers-deploy-canfail-malware-against-ukraine.html 4. CISA Alerts on Critical ZLAN ICS Flaws Allowing Full Device Takeover CISA has issued a critical advisory for severe vulnerabilities in ZLAN5143D serial-to-Ethernet device servers used in industrial control systems. These flaws enable attackers to gain full control over affected devices, risking disruption of critical infrastructure operations. Sources: Cvefeed, Gbhackers https://gbhackers.com/cisa-issues-alert-on-zlan-ics-flaws-enabling-full-device-takeover/ 5. Critical Command Injection Vulnerabilities in Comfast CF-N1 V2 Firmware Two remote command injection vulnerabilities (CVE-2026-2534 and CVE-2026-2535) affect Comfast CF-N1 V2 2.6.0.2 via the mbox-config CGI interface. Both exploits have been publicly disclosed and can be leveraged by attackers to execute arbitrary commands remotely. The vendor has not responded to early notifications, increasing the risk of widespread exploitation. Sources: Cvefeed https://cvefeed.io/vuln/detail/CVE-2026-2535 Stay sharp. Stay secure. #NerdieNews #InfoSec #CyberSecurity #TechNews #DataSecurity #CyberThreats

    Post summary

    The article provides a disclosure of several CVEs with technical details but no proof‑of‑concept, exploit code, active exploitation claims, or patch information.

    0001034
    54 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-26369 Privilege Escalation in eNet SMART HOME Server via Unauthorized Group Modification https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-26369

    Post summary

    CVE-2026-26369 discloses a privilege‑escalation flaw in eNet SMART HOME Server caused by unauthorized group modification.

    0001041
    4.0K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-26369 (CVSS:9.3, CRITICAL) is Undergoing Analysis. eNet SMART HOME server 2.2.1 and 2.3.1 contains a privilege escalation vulnerability due to insufficient authorization c..https://nvd.nist.gov/vuln/detail/CVE-2026-26369 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The tweet announces a critical privilege‑escalation flaw in eNet SMART HOME server (CVE-2026-26369) with a CVSS 9.3 score, but does not provide a PoC, exploit code, or patch information.

    0000033
    171 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-26369 - Critical eNet SMART HOME server 2.2.1 and 2.3.1 contains a privilege escalation vulnerability due to insufficient authorization checks in the setUserGroup JSON-RPC method. A low-privileged user (U... https://www.thehackerwire.com/vulnerability/CVE-2026-26369/ https://t.co/qPw4Cragub

    Post summary

    CVE‑2026‑26369 is a privilege escalation flaw in eNet SMART HOME server 2.2.1/2.3.1 caused by missing authorization checks in the setUserGroup JSON‑RPC method. No PoC, exploit, or patch details are disclosed.

    0000047
    112 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Disclosure

    🚨 CRITICAL: CVE-2026-26369 in JUNG eNet SMART HOME server lets low-priv users escalate to admin via /jsonrpc/management. Versions 2.2.1 & 2.3.1 at risk. Restrict access & monitor logs! 🔒 https://radar.offseq.com/threat/cve-2026-26369-improper-privilege-management-in-ju-f86570e... https://t.co/6ycNs8Zvtu

    Post summary

    The tweet alerts to CVE-2026-26369, a critical privilege escalation flaw in JUNG eNet SMART HOME server (v2.2.1/2.3.1), and recommends restricting access and monitoring logs as mitigations.

    0000050
    265 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Disclosure

    🔴 CRITICAL: CVE-2026-26369 lets low-privileged users gain admin access on JUNG eNet SMART HOME server (2.2.1, 2.3.1) — risking total system takeover! Restrict access & monitor NOW. https://radar.offseq.com/threat/cve-2026-26369-improper-privilege-management-in-ju-f86570ed #Off... https://t.co/NGu06WaNTz

    Post summary

    This advisory announces a critical privilege escalation vulnerability in the JUNG eNet SMART HOME server that enables low‑privileged users to obtain admin rights, and urges users to restrict access and monitor the system.

    0000040
    265 followersView on X
  • Säkerhetsbloggen@Sakerhetsblogg
    General

    CVE-2026-26369 i eNet SMART HOME visar hur lågtprivilegierade användare kan höja sina behörigheter genom att utnyttja brister i auktorisering. Detta kan leda till fullständig administrativ kontroll över smarta hem-funktioner. #säkerhet #cybersäkerhet #CVE

    Post summary

    The tweet briefly mentions CVE‑2026‑26369 as a privilege‑escalation flaw in eNet Smart Home but offers no additional technical detail, exploitation evidence, or mitigation information.

    0000029
    7 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26369 eNet SMART HOME server 2.2.1 and 2.3.1 contains a privilege escalation vulnerability due to insufficient authorization checks in the setUserGroup JSON-RPC method. A l… https://www.cve.org/CVERecord?id=CVE-2026-26369

    Post summary

    CVE-2026-26369 is a privilege escalation vulnerability in eNet SMART HOME server caused by insufficient authorization checks in the setUserGroup JSON‑RPC method; no PoC, exploit, patch, or active exploitation information is provided.

    00000554
    56.4K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appjung-groupenet_smart_home2.2.1--
Appjung-groupenet_smart_home2.3.1--

Explore more