Skip to main content

Tags › Enswitch

Enswitch: Password reset authentication bypass

Published on Oct 1, 2026 in ,

  • CVSS v4.0, Enable Security assessment
    • Exploitability: High
    • Complexity: Low
    • Vulnerable system: High
    • Subsequent system: None
    • Exploitation: High
    • Security requirements: High
    • Vector: link
  • Exploitation status: abused in the wild before public disclosure
  • Other references:
  • CVE: not assigned as of 2026-10-01
  • Vendor-reported fixed builds:
    • Enswitch 3.13 to 4.3: Subversion revision 21680 or later
    • Enswitch 4.4: Git commit c2c981578 or later
  • Tested vulnerable version: Enswitch 4.2
  • Tested fixed build: vendor-provided Enswitch 4.4 build at Git commit c2c981578, tested 2026-07-07
  • Affected versions:
    • Enswitch 4.2 was confirmed vulnerable.
    • Integrics reported that supported Enswitch 3.13 through 4.4 branches required the fixes listed above. Enable Security did not independently test every affected branch.
  • Timeline:
    • First discovery and report to Integrics: 2026-07-03
    • Integrics acknowledged the report and supplied fixes for testing: 2026-07-03
    • Fixes released to customers: 2026-07-06
    • Enable Security tested the Enswitch 4.4 fix: 2026-07-07
    • Enable Security advisory: 2026-10-01

TL;DR

Enswitch 4.2 contained an authentication bypass in the /api/json/user/password/update/ API endpoint. If an account had no pending password reset, an unauthenticated attacker who knew its username could set a new password without supplying a valid reset key. The endpoint also returned distinguishable application-level JSON responses for existing and nonexistent usernames. The vulnerability was abused in the wild before public disclosure. Integrics supplied fixes for supported Enswitch branches, and Enable Security tested the vendor-provided Enswitch 4.4 fix. No CVE had been assigned by the publication date.

…

Read more about Enswitch: Password reset authentication bypass

Enswitch password reset bypass advisory

We published a security advisory for Enswitch covering an authentication bypass in the password reset API. An unauthenticated attacker who knew a username could set the account password without a valid reset key, and the same endpoint also leaked whether a username existed. The issue was abused in the wild before public disclosure. Integrics had a fix the same day we reported it and released it to customers three days later.…

Read more about Enswitch password reset bypass advisory