THREAT OPS › Threat News › [NVD] CVE-2026-26369 (HIGH 8.8) — eNet SMART HOME server 2.2.1 and 2.3.1 contains a privilege escalation vulnerability due to insufficient authorization checks in the setUserGroup JSON-RPC method. A low-privileged user (UG_USER) can send a crafted POST request to /jsonrpc/management specifying their own username
[NVD] CVE-2026-26369 (HIGH 8.8) — eNet SMART HOME server 2.2.1 and 2.3.1 contains a privilege escalation vulnerability due to insufficient authorization checks in the setUserGroup JSON-RPC method. A low-privileged user (UG_USER) can send a crafted POST request to /jsonrpc/management specifying their own username
CVE-2026-26369 CVSS: 8.8 HIGH Published: 2026-02-15T16:15:54.407
eNet SMART HOME server 2.2.1 and 2.3.1 contains a privilege escalation vulnerability due to insufficient authorization checks in the setUserGroup JSON-RPC method. A low-privileged user (UG_USER) can send a crafted POST request to /jsonrpc/management specifying their own username to elevate their account to the UG_ADMIN group, bypass
Indicators of compromise
- CVE-2026-26369cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-26369