CVE 7.1 HIGH

JUNG eNet SMART HOME server 2.2.1/2.3.1 Arbitrary User Deletion via deleteUserAccount_CVE-2026-26367

7.1 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Description

eNet SMART HOME server 2.2.1 and 2.3.1 contains a missing authorization vulnerability in the deleteUserAccount JSON-RPC method that permits any authenticated low-privileged user (UG_USER) to delete arbitrary user accounts, except for the built-in admin account. The application does not enforce role-based access control on this function, allowing a standard user to submit a crafted POST request to /jsonrpc/management specifying another username to have that account removed without elevated permissions or additional confirmation.

Basic Information

ID CVE-2026-26367
Source VulnCheck
Published Feb 15, 2026 at 15:29

Affected Product

Vendor JUNG
Product eNet SMART HOME server
Version 2.3.1 (46841)
Affected Versions JUNG eNet SMART HOME server 2.3.1 (46841)
JUNG eNet SMART HOME server 2.2.1 (46056)

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.