PatchSiren

Integrics CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Integrics CVE published 2026-10-08

CVE-2026-107640

CVE-2026-107640 is a critical authentication bypass vulnerability in Integrics Enswitch versions 3.13 through 4.4. The vulnerability allows unauthenticated attackers to change account passwords via the Password Reset API by omitting the reset parameter. This could lead to the takeover of administrator accounts after enumerating valid usernames. The vulnerability exists in the /api/json/user/password/updat [truncated]