Executive brief
ShizenBox2 is an edge computing appliance used to manage and run applications at network endpoints. An authenticated attacker can exploit a user-controlled key vulnerability to bypass authorization checks and change other users' passwords, potentially enabling unauthorized account takeover and lateral movement within the system.
Technical details
The vulnerability is an authorization bypass issue (CWE-639) caused by improper validation of user-controlled cryptographic keys in the edge-app component. An attacker who has valid login credentials can leverage this flaw to modify passwords of other user accounts without proper authorization checks. The attack requires network access and valid authentication credentials. A successful exploit results in privilege escalation and account compromise. Updates to version 3.1.16 or later are available from Shizen Connect Inc.
Affected products
- Shizen Connect Inc. ShizenBox2 3.1.15 and earlier
Timeline
- 2026-09-02: disclosed
- 2026-09-03: advisory: NVD publication