{"id":"CVE-2026-75960","title":"Rently Smart Home versions 20.1.0 and prior are vulnerable to an Insufficiently Protected Credentials vulnerability","summary":"Rently Smart Home versions 20.1.0 and prior are vulnerable to an Insufficiently Protected Credentials vulnerability. This could allow an attacker to retrieve pins including the Master Pin, overriding standard user permissions.","severity":"high","cvss":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","cwe":["CWE-522"],"published":"2026-08-26","updated":"2026-09-08","sourceUpdated":"2026-09-08T19:30:43.093","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-75960","references":[{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-01","label":"ics-cert@hq.dhs.gov"}],"tags":["nvd"],"epss":0.0035,"epssPercentile":0.28677,"ingestedAt":"2026-09-08T20:10:03.158Z","slug":"CVE-2026-75960","body":"## Overview\n\nRently Smart Home versions 20.1.0 and prior are vulnerable to an Insufficiently Protected Credentials vulnerability. This could allow an attacker to retrieve pins including the Master Pin, overriding standard user permissions.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":44.6,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}