External risk intelligence

Integrics Enswitch Authentication Bypass via Password Reset API

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-107640

Integrics Enswitch is a telecommunications platform commonly deployed with public-facing web interfaces and API endpoints for user management. The vulnerability exists within a web API path (/api/json/user/password/update/) that is reachable without authentication, making it an internet-accessible service by design in typical deployments.

Authentication Bypass

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in Integrics Enswitch software could allow unauthorized access to administrator accounts by bypassing the password reset process. This could potentially lead to the compromise of sensitive systems and data.

  • Bypasses password reset to gain admin access.
  • Allows attackers to take over administrator accounts.
  • Confirm relevance and exposure for Integrics Enswitch.

Attack Path

How an attacker could exploit the issue

An attacker can bypass authentication to change account passwords by accessing a specific API endpoint without a reset parameter. This allows them to target accounts where the reset key is not used, potentially taking over administrator accounts after discovering valid usernames.

  • No authentication is required to access the endpoint.
  • Omitting the reset parameter triggers the vulnerability.
  • Allows unauthorized administrator account takeover.

Live Threat

Current exploitation, exposure, and threat context

An authentication bypass vulnerability in the password update API could allow unauthenticated attackers to change account passwords. This could occur when targeting accounts that do not have a pending reset, as an empty reset key can match the default value. By enumerating valid usernames, an attacker could potentially take over administrator accounts.

  • Administrator account credentials.
  • Exploiting a vulnerable password reset API.
  • Account takeover.

Operational Fix

Recommended remediation, mitigation, and detection steps

Systems owners and platform teams are likely responsible for securing Integrics Enswitch deployments. The first practical step is to identify all instances of Enswitch, confirm their reachability and business criticality, locate the accountable owner, and then prioritize remediation based on assessed risk.

  • Platform owners should manage this issue.
  • Verify Enswitch deployment reachability.
  • Plan maintenance for remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Integrics Enswitch?

Integrics Enswitch is a specialized telecommunications software platform. It is primarily used by service providers and businesses to manage telephony services, including call routing, billing, and user management through integrated web interfaces and API endpoints.

What does CWE-640 mean for CVE-2026-107640?

CWE-640 refers to an authentication bypass vulnerability involving weak password reset mechanisms. In this specific CVE, the system fails to correctly validate the reset process, allowing an attacker to change an account's password without providing the necessary proof of identity or authorization.

How do attackers trigger this password bypass?

An attacker can exploit this by sending a request to a specific API path while omitting the required reset parameter. The vulnerability occurs when the system defaults to an empty reset key, which matches the empty value provided by the attacker, thereby bypassing the check for accounts that do not have a pending password reset.

Why is this CVE considered internet-facing?

Halo Surface Signal notes that Integrics Enswitch is typically deployed with web interfaces and API endpoints accessible over the network. Because the vulnerable password reset path is reachable without requiring prior authentication, these deployments are often directly exposed to remote, unauthenticated access from the internet.

What should I do if I run Enswitch?

First, locate and inventory all Enswitch instances within your environment to determine their reachability. Once identified, confirm the business criticality of each instance and coordinate with the appropriate platform owners to apply the necessary security updates or configuration changes.

References