Skip to main content

Enswitch password reset bypass advisory

TL;DR

We published a new advisory for Enswitch, the VoIP softswitch and hosted PBX platform from Integrics. The password reset API let anyone who knew a username set a new password for that account, without ever receiving the reset email. The same endpoint also leaked which usernames were valid. We rate it CVSS v4.0 9.3 (Critical), and it was abused in the wild before public disclosure. Integrics had a fix the same day we reported it and released it to their customers three days later.

Full details: ES2026-06: Enswitch password reset authentication bypass.

What we found

The /api/json/user/password/update/ endpoint is the back half of the forgotten-password flow. The user clicks the link in a password-reset email, and the API handler is supposed to require a reset parameter containing the key from that URL before it changes the password.

On Enswitch 4.2, the check looked something like this:

  • An omitted reset parameter defaulted to an empty string.
  • For an account with no pending password reset, the stored reset_key was NULL or empty.
  • Perl’s string comparison coerces undef to an empty string, so the supplied and stored values compared equal.
  • The handler then changed the account password.

What could possibly go wrong? Any account in the people table whose stored reset key happened to be NULL or empty, which in practice is most of them most of the time, could be taken over by someone who knew the username. No email access, no man in the middle, no prior authentication.

The same endpoint also returned different JSON codes for existing versus nonexistent usernames when a deliberately wrong but non-empty reset value was supplied, which is enough to walk through a list and find valid accounts.

The pattern to watch for in your own code

The root cause is a small, familiar kind of mistake. The security-sensitive invariant was “the caller must prove they received the reset email”, but it was expressed as an equality check that silently held when neither side had any value at all. undef eq "" is true in Perl, and that was enough to turn an authenticated password change into an unauthenticated one.

The patched handler fixes it the way you would want: require the supplied reset value to be non-empty before comparing, and return the same rejection response whether the account is missing or the key is wrong.

Perhaps you are wondering whether your own password reset flows have the same shape. If you have ever compared a user-supplied token against a stored token without first checking that both are non-empty, this is a good moment to go and look.

How to check if you’re affected

Enswitch 4.2 is confirmed vulnerable. Integrics reported that supported Enswitch 3.13 through 4.4 branches needed the fix. We did not independently test every branch.

Apply the applicable Integrics fix:

  • Enswitch 3.13 to 4.3: Subversion revision 21680 or later
  • Enswitch 4.4: Git commit c2c981578 or later

If you cannot patch immediately, restrict access to /api/json/user/password/update/ to trusted clients, or block the route at the edge until the fix is in place.

Do keep in mind that this was abused in the wild before public disclosure, so if you run an older Enswitch build and have not rotated credentials recently, it is worth reviewing recent password changes and login activity for any account whose owner did not actually request a reset.

Timeline

  • 2026-07-03: First discovery and report to Integrics. Integrics acknowledged, developed the fix, and supplied it to us for testing the same day.
  • 2026-07-06: Integrics released the fix to their customers.
  • 2026-07-07: We tested the vendor-provided Enswitch 4.4 build and confirmed both issues are closed.
  • 2026-10-01: This advisory published.

Thanks

Thanks to the Integrics team for the fast turnaround and for working with us on testing the fix.

Full technical details

The advisory has the request and response table, copy-pasteable reproduction commands, affected versions, and the full disclosure timeline:

ES2026-06: Enswitch password reset authentication bypass

If you run Enswitch or any other VoIP platform and want someone to go looking for this kind of bug before an attacker does, that is what we do.