7.1
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Description
eNet SMART HOME server 2.2.1 and 2.3.1 contains a missing authorization vulnerability in the deleteUserAccount JSON-RPC method that permits any authenticated low-privileged user (UG_USER) to delete arbitrary user accounts, except for the built-in admin account. The application does not enforce role-based access control on this function, allowing a standard user to submit a crafted POST request to /jsonrpc/management specifying another username to have that account removed without elevated permissions or additional confirmation.
Basic Information
ID
CVE-2026-26367
Source
VulnCheck
Published
Feb 15, 2026 at 15:29
Affected Product
Vendor
JUNG
Product
eNet SMART HOME server
Version
2.3.1 (46841)
Affected Versions
JUNG eNet SMART HOME server 2.3.1 (46841)
JUNG eNet SMART HOME server 2.2.1 (46056)
JUNG eNet SMART HOME server 2.2.1 (46056)