---
title: Enswitch: Password reset authentication bypass
date: 2026-10-01
url: /advisories/ES2026-06-enswitch-password-reset-bypass.md
---

- CVSS v4.0, Enable Security assessment
    - Exploitability: High
    - Complexity: Low
    - Vulnerable system: High
    - Subsequent system: None
    - Exploitation: High
    - Security requirements: High
    - Vector: [link](https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N)
- Exploitation status: abused in the wild before public disclosure
- Other references:
    - [CWE-287: Improper Authentication](https://cwe.mitre.org/data/definitions/287.html)
    - [CWE-640: Weak Password Recovery Mechanism for Forgotten Password](https://cwe.mitre.org/data/definitions/640.html)
- CVE: not assigned as of 2026-10-01
- Vendor-reported fixed builds:
    - Enswitch 3.13 to 4.3: Subversion revision 21680 or later
    - Enswitch 4.4: Git commit c2c981578 or later
- Tested vulnerable version: Enswitch 4.2
- Tested fixed build: vendor-provided Enswitch 4.4 build at Git commit c2c981578, tested 2026-07-07
- Affected versions:
    - Enswitch 4.2 was confirmed vulnerable.
    - Integrics reported that supported Enswitch 3.13 through 4.4 branches required the fixes listed above. Enable Security did not independently test every affected branch.
- Timeline:
    - First discovery and report to Integrics: 2026-07-03
    - Integrics acknowledged the report and supplied fixes for testing: 2026-07-03
    - Fixes released to customers: 2026-07-06
    - Enable Security tested the Enswitch 4.4 fix: 2026-07-07
    - Enable Security advisory: 2026-10-01

## TL;DR

Enswitch 4.2 contained an authentication bypass in the `/api/json/user/password/update/` API endpoint. If an account had no pending password reset, an unauthenticated attacker who knew its username could set a new password without supplying a valid reset key. The endpoint also returned distinguishable application-level JSON responses for existing and nonexistent usernames. The vulnerability was abused in the wild before public disclosure. Integrics supplied fixes for supported Enswitch branches, and Enable Security tested the vendor-provided Enswitch 4.4 fix. No CVE had been assigned by the publication date.

## Description

The Enswitch API endpoint `/api/json/user/password/update/` allows users to set a new password as part of a forgotten-password reset flow. The caller is expected to supply a `reset` parameter containing the reset key delivered to the user in a password-reset URL.

In the vulnerable implementation, an omitted `reset` parameter defaults to an empty string. When the target account has no pending password reset, its stored `reset_key` is NULL or empty. Perl string comparison coerces an undefined value to an empty string, so the supplied and stored values compare equal. The handler then changes the account password even though the caller did not possess a valid reset key.

The endpoint can also disclose whether a username exists. When a deliberately incorrect, non-empty reset value is supplied, a nonexistent username and an existing username produce different application-level JSON codes and response bodies. In observed testing, the HTTP transport status was 200 in both cases; the distinguishing values were inside the JSON response.

## Technical details

The vulnerable handler performs these operations:

1. Read `username`, `reset`, and `password`, using an empty-string default for omitted parameters.
2. Look up the supplied username in the `people` table.
3. Return application code 204 when no matching row exists.
4. Compare the supplied reset value with the stored `reset_key` using Perl string equality.
5. Update the password when the comparison succeeds.

For an existing account with no pending reset, both values become empty strings and the comparison succeeds. The vendor patch requires a non-empty supplied reset value and uses a uniform rejection response when the account does not exist or the key does not match.

| Request condition | Vulnerable application-level result |
|---|---|
| Nonexistent username with an incorrect, non-empty reset value | JSON code 204 |
| Existing username with an incorrect, non-empty reset value | JSON code 403 |
| Existing username with no pending reset and omitted or empty reset value | JSON code 204 and password changed |

A valid pending reset key follows the intended password-reset path and is not represented in this table.

## Impact

An unauthenticated remote attacker who knows a valid username can reset the password of an account whose stored reset key is NULL or empty. Any account represented in the `people` table could be affected, potentially including administrator accounts. Enable Security did not independently verify every account type or authentication path. Successful exploitation permits account takeover without access to the legitimate password-reset message; the resulting confidentiality and integrity impact depends on the compromised account's privileges and available data.

The differential JSON responses can help an attacker identify valid usernames. Enable Security confirmed the authentication bypass on Enswitch 4.2 but did not independently test every supported branch. Enable Security is aware of this vulnerability being abused in the wild before public disclosure.

## How to reproduce the issue

Only run these requests against an Enswitch instance you own or are explicitly authorized to test. Use a disposable test account and have a recovery plan. The password-reset request changes the account password, and the username and new password may be recorded in command history, process listings, proxy logs, and web-server logs.

### Password-reset bypass

On a vulnerable Enswitch 4.2 system, send a password-update request for a disposable account that has no pending password reset. Deliberately omit the `reset` parameter:

```bash
curl --get --silent --show-error \
  --data-urlencode 'username=disposable-test-user' \
  --data-urlencode 'password=Temporary-Test-Password-Change-Me' \
  'https://<authorized-test-host>/api/json/user/password/update/'
```

The vulnerable endpoint returns a JSON response with application-level code 204 and changes the disposable account's password. The patched endpoint returns application-level code 403 and does not change the password.

After testing, restore the disposable account through the normal authenticated password-change workflow, delete it, or restore the test system snapshot.

### Username enumeration

Use the same deliberately invalid reset value for one known disposable username and one random nonexistent username:

```bash
curl --get --silent --show-error \
  --data-urlencode 'username=disposable-test-user' \
  --data-urlencode 'password=unused' \
  --data-urlencode 'reset=INVALID-RESET-KEY-NOT-ISSUED-BY-ENSWITCH' \
  'https://<authorized-test-host>/api/json/user/password/update/'

curl --get --silent --show-error \
  --data-urlencode 'username=nonexistent-random-test-user' \
  --data-urlencode 'password=unused' \
  --data-urlencode 'reset=INVALID-RESET-KEY-NOT-ISSUED-BY-ENSWITCH' \
  'https://<authorized-test-host>/api/json/user/password/update/'
```

The vulnerable endpoint returns distinguishable JSON responses, typically application-level code 403 for the existing username and 204 for the nonexistent username. The vendor-patched handler returns the same rejection code for both requests.

## Solutions and recommendations

Apply the applicable Integrics fix:

- Enswitch 3.13 to 4.3: Subversion revision 21680 or later
- Enswitch 4.4: Git commit c2c981578 or later

Integrics supplied fixes on 2026-07-03 and released them to customers on 2026-07-06. Enable Security tested the vendor-provided Enswitch 4.4 build on 2026-07-07 and confirmed that it prevented both the password-reset authentication bypass and the username-enumeration behavior.

If the fix cannot be installed immediately, restrict access to `/api/json/user/password/update/` to trusted clients or temporarily block the route.

## Acknowledgements

Enable Security thanks Integrics for acknowledging the report and supplying fixes promptly.

## References

- [Enswitch product page](https://www.integrics.com/enswitch/)
- [CWE-287: Improper Authentication](https://cwe.mitre.org/data/definitions/287.html)
- [CWE-640: Weak Password Recovery Mechanism for Forgotten Password](https://cwe.mitre.org/data/definitions/640.html)

## About Enable Security

[Enable Security](https://www.enablesecurity.com) provides quality penetration testing to help protect your real-time communications systems against attack.

## Disclaimer

The information in the advisory is believed to be accurate at the time of publishing based on currently available information. Use of the information constitutes acceptance for use in an AS IS condition. There are no warranties with regard to this information. Neither the author nor the publisher accepts any liability for any direct, indirect, or consequential loss or damage arising from use of, or reliance on, this information.

## Disclosure policy

This report is subject to Enable Security's vulnerability disclosure policy which can be found at <https://github.com/EnableSecurity/Vulnerability-Disclosure-Policy>.

