CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-75960

criticalcovered by 1 sourcefirst seen 2026-08-25
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to access sensitive information and override user permissions. The following versions of Rently Smart Home are affected: Smart Home <=20.1.0 CVSS Vendor Equipment Vulnerabilities v3 8.1 Rently Rently Smart Home Insufficiently Protected Credentials Background Critical Infrastructure Sectors: Commercial Facilities, Communications, Information Technology Countries/Areas Deployed: United States, India Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-75960 Rently Smart Home versions 20.1.0 and prior are vulnerable to an Insufficiently Protected Credentials vulnerability. This could allow an attacker to retrieve pins including the Master Pin, overriding standard user permissions. View CVE Details Affected Products Rently Smart Home Vendor: Rently Product Version: Rently Smart Home: <=20.1.0 Product Status: known_affected Remediations Mitigation Rently has patched this vulnerability in late June. No user action is required. Mitigation For more information, contact Rently (support@rently.com). mailto:support@rently.com Relevant CWE: CWE-522 Insufficiently Protected Credentials Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.1 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N 4.0 8.7 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Acknowledgments Berk Dusunur reported this vulnerability to CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from

CSIRTS triage

What
Rently Smart Home stores credentials insufficiently protected, allowing attackers to retrieve PIN codes including the master PIN and override user permissions.
Who is affected
Rently Smart Home deployments version 20.1.0 and earlier worldwide.
Urgency
Critical; insufficient credential protection allows attackers to extract master PINs and bypass access controls.
Action
Update Rently Smart Home to version 20.1.1 or later with improved credential protection.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-75960

Get an email if CVE-2026-75960 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2026-75960

CVE.org record

Embed the live status

CVE-2026-75960 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-75960 status](https://www.csirts.com/badge/CVE-2026-75960)](https://www.csirts.com/cve/CVE-2026-75960)