High‑Severity Credential Exposure (CVE‑2026‑75960) in Rently Smart Home Could Let Attackers Override User Permissions
What It Is — Rently Smart Home versions ≤ 20.1.0 contain an Insufficiently Protected Credentials flaw (CVE‑2026‑75960). The vulnerability allows an attacker who can reach the device to retrieve stored PINs, including the Master Pin, and thereby bypass normal user‑permission checks.
Exploitability — CVSS 3.1 base score 8.1 (HIGH). The advisory notes that successful exploitation would give direct access to sensitive credentials; a patch was released in late June 2024. No public PoC is known, but the attack vector is network‑accessible (AV:N).
Affected Products — Rently Smart Home ≤ 20.1.0 (smart‑home controller used in commercial facilities, communications and IT environments).
Why It Matters for Compliance & Audit Readiness
- SOC 2 CC6.1 (Logical Access Controls) requires that credentials be protected against unauthorized disclosure; this flaw demonstrates a gap that auditors will probe.
- Continuous evidence of credential‑management practices (encryption, rotation, privileged‑access logging) is essential to show due diligence during a SOC 2 audit.
- Enterprise buyers increasingly demand proof that SaaS and IoT providers have mature access‑control processes; a known credential exposure can stall contracts.
Recommended Actions
- Verify that every Rently Smart Home deployment is running a version > 20.1.0; apply the vendor patch immediately.
- Conduct a credential‑storage review: ensure PINs are encrypted at rest, enforce strong rotation policies, and limit exposure to least‑privilege services.
- Update your access‑control policies to reflect the new patch status and document the change in your SOC 2 control evidence repository.
- Enable continuous monitoring of privileged‑access logs and set alerts for any anomalous PIN‑retrieval activity.
Source: CISA Advisory – ICSA‑26‑237‑01