CRITICAL
9.1 CVE-2026-107640 Published 8 Oct 2026
Integrics Enswitch Authentication Bypass in Password Update API
Worried this affects your website?
Integrics Enswitch versions 3.13 through 4.4 are affected by an authentication bypass vulnerability in the password update API endpoint.
An unauthenticated attacker can change account passwords by omitting the reset parameter in requests to /api/json/user/password/update/. This works for accounts with no pending reset, as their empty reset_key matches the defaulted empty value.
Attackers can enumerate valid usernames and then take over administrator accounts.
- Affected versions: 3.13 through 4.4
- Attack vector: unauthenticated HTTP requests to the API
- Impact: full account takeover, including administrator accounts
Reference: CVE-2026-107640 on NVD
← Back to Security News