Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-26369
JUNG eNet SMART HOME server 2.2.1/2.3.1 Privilege Escalation via setUserGroup
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N L N H H H 8.7 .0052 42.2 —
AFFECTED
Product Versions Fixed
eNet SMART HOME server 2.3.1 (46841) – —
TIMELINE
Feb 15 Reserved by VulnCheck
Feb 15 Published (CNA: VulnCheck)
Aug 24 EXPLOIT PUBLISHED — CVE-2026-26369 (JUNG eNet SMART HOME server). Public exploit reference added.
Description
eNet SMART HOME server 2.2.1 and 2.3.1 contains a privilege escalation vulnerability due to insufficient authorization checks in the setUserGroup JSON-RPC method. A low-privileged user (UG_USER) can send a crafted POST request to /jsonrpc/management specifying their own username to elevate their account to the UG_ADMIN group, bypassing intended access controls and gaining administrative capabilities such as modifying device configurations, network settings, and other smart home system functions.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| February 15, 2026 | Reserved | Reserved by VulnCheck |
| February 15, 2026 | Published | Published (CNA: VulnCheck) |
| August 24, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-26369 (JUNG eNet SMART HOME server). Public exploit reference added. |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| JUNG | eNet SMART HOME server | — | 2.3.1 (46841) | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-26369 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.