Description
Authorization bypass through user-controlled key issue exists in ShizenBox2 (edge-app). If exploited, an attacker who can log in to the product may change the other user's password.
Published: 2026-09-03
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authorization bypass flaw exists that allows an attacker who can log in to ShizenBox2 to change another user’s password by supplying a user-controlled key. The vulnerability is a privilege escalation within the application, enabling an attacker to impersonate other users or initiate further attacks from that account.

Affected Systems

The affected system is the ShizenBox2 edge‑app from Shizen Connect Inc. No specific version information is supplied in the CVE entry, so all released builds of ShizenBox2 are potentially vulnerable until a patch is applied.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity. The EPSS score is not available, but the lack of a KEV listing suggests no publicly known exploit at the time of reporting. Exploitation requires the attacker to possess valid credentials to log in to the product; once logged in, the flaw can be abused without additional network access. The risk is considered high for environments where account isolation is critical.

Generated by OpenCVE AI on September 3, 2026 at 12:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the vendor’s security fix or patch for ShizenBox2 when it becomes available
  • Enforce least privilege so that logged‑in users have only the permissions necessary for their role
  • Enable multi‑factor authentication to protect user accounts and reduce the impact if passwords are changed maliciously

Generated by OpenCVE AI on September 3, 2026 at 12:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Shizen Connect
Shizen Connect shizenbox2 (edge-app)
Vendors & Products Shizen Connect
Shizen Connect shizenbox2 (edge-app)

Thu, 03 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 03 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Title Authorization Bypass via User‑Controlled Key Allows Password Change

Thu, 03 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Description Authorization bypass through user-controlled key issue exists in ShizenBox2 (edge-app). If exploited, an attacker who can log in to the product may change the other user's password.
Weaknesses CWE-639
References
Metrics cvssV3_0

{'score': 6.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Shizen Connect Shizenbox2 (edge-app)
cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-09-03T13:11:07.938Z

Reserved: 2026-08-26T06:06:54.184Z

Link: CVE-2026-80254

cve-icon Vulnrichment

Updated: 2026-09-03T13:11:02.935Z

cve-icon NVD

Status : Deferred

Published: 2026-09-03T13:06:10.737

Modified: 2026-09-03T17:30:37.197

Link: CVE-2026-80254

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T15:33:27Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key