CVE-2026-80254
—Authorization bypass in ShizenBox2 edge-app lets users change other users' passwords
ShizenBox2 (edge-app) contains an authorization bypass through a user-controlled key (CWE-639) in its user-account management functionality. A low-privileged, authenticated user can submit a password-change request that references another user's identifier, and the application fails to verify that the requester is authorized to modify that account, allowing the change to succeed. Successful exploitation allows an attacker to change another user's password and potentially take over that account, with high integrity impact but no direct confidentiality or availability impact per the CVSS 4.0 vector. Any deployment of ShizenBox2 (edge-app) where multiple users hold accounts is potentially affected, though the product's install base is not publicly documented. As of this analysis there is no public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates about a 0.4% probability of exploitation within 30 days.
What to do: Contact the ShizenBox2 vendor to obtain the affected/fixed version ranges and apply the patched release as soon as it is available. In the meantime, restrict which users hold valid logins, audit accounts for password changes you did not initiate, and monitor JPCERT/CC advisories for remediation details.
| ShizenBox2 (edge-app) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Authorization bypass through user-controlled key issue exists in ShizenBox2 (edge-app). If exploited, an attacker who can log in to the product may change the other user's password.
- Weakness
- CWE-639
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.