CVE-2026-107640: Integrics Enswitch
Critical severity, CVSS 9.1. EPSS: 0.4% chance of exploitation in the next 30 days.
Integrics Enswitch 3.13 through 4.4 contains an authentication bypass vulnerability in /api/json/user/password/update/ that allows unauthenticated attackers to change account passwords by omitting the reset parameter. Attackers can target accounts with no pending reset, whose empty reset_key matches the defaulted empty value, to take over administrator accounts after enumerating valid usernames.
Affected products
- Integrics Enswitch: from 3.13, up to and including 4.4
Published 2026-10-08. Last modified 2026-10-08.