Junglewise Threat Intelligence

CVE-2026-75960: Rently Smart Home insufficiently protected credentials

CVE-2026-75960 · Severity: high · CVSS 8.1 · Published 2026-08-26

Executive brief

Rently Smart Home is a smart lock and access control system used in residential properties and commercial facilities. A vulnerability in versions 20.1.0 and prior allows attackers with basic network access to retrieve PIN codes including master PINs, potentially granting unauthorized entry to secured properties and bypassing user permission controls. This could lead to property intrusions, theft, and loss of tenant privacy.

Technical details

The vulnerability is an insufficiently protected credentials issue (CWE-522) affecting Rently Smart Home versions 20.1.0 and prior. An authenticated attacker can exploit weak credential storage to retrieve PIN codes, including the master PIN, via network access without additional user interaction. Successful exploitation allows the attacker to bypass standard access controls and permission restrictions on the smart lock system. The vulnerability has been patched by Rently as of late June 2026; users should upgrade to versions after 20.1.0 to remediate.

Affected products

  • Rently Smart Home 20.1.0 and prior

Timeline

  • 2026-08-25: disclosed
  • 2026-06: patched: Patch released in late June 2026

References