CRITICAL
Integrics
CVE published 2026-10-08
CVE-2026-107640
CVE-2026-107640 is a critical authentication bypass vulnerability in Integrics Enswitch versions 3.13 through 4.4. The vulnerability allows unauthenticated attackers to change account passwords via the Password Reset API by omitting the reset parameter. This could lead to the takeover of administrator accounts after enumerating valid usernames. The vulnerability exists in the /api/json/user/password/updat [truncated]