---
id: CVE-2026-26369
title: >-
  eNet SMART HOME server 2.2.1 and 2.3.1 contains a privilege escalation
  vulnerability due to insufficient authorization checks in the setUserGroup
  JSON-RPC method
summary: >-
  eNet SMART HOME server 2.2.1 and 2.3.1 contains a privilege escalation
  vulnerability due to insufficient authorization checks in the setUserGroup
  JSON-RPC method. A low-privileged user (UG_USER) can send a crafted POST
  request to /jsonrp…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-269
vendor: jung-group
product: enet_smart_home
affected:
  - enet_smart_home = 2.2.1
  - enet_smart_home = 2.3.1
published: '2026-02-15'
updated: '2026-08-24'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-26369'
references:
  - url: >-
      https://www.vulncheck.com/advisories/jung-enet-smart-home-server-privilege-escalation-v
    label: disclosure@vulncheck.com
  - url: 'https://www.zeroscience.mk/en/vulnerabilities/ZSL-2026-5975.php'
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00521
epssPercentile: 0.41925
ingestedAt: '2026-08-24T12:02:50.098Z'
---

## Overview

eNet SMART HOME server 2.2.1 and 2.3.1 contains a privilege escalation vulnerability due to insufficient authorization checks in the setUserGroup JSON-RPC method. A low-privileged user (UG_USER) can send a crafted POST request to /jsonrpc/management specifying their own username to elevate their account to the UG_ADMIN group, bypassing intended access controls and gaining administrative capabilities such as modifying device configurations, network settings, and other smart home system functions.

## Affected

- `enet_smart_home = 2.2.1`
- `enet_smart_home = 2.3.1`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
