highOther

Rently Smart Home Insufficiently Protected Credentials Vulnerability (CVE-2026-75960)

First seen Aug 26, 2026 · Updated Aug 26, 2026 · CVSS 8.1

ICSIoTsmart-homecredential-exposureCWE-522vulnerability-disclosure

Rently Smart Home versions 20.1.0 and earlier contain a vulnerability that insufficiently protects credentials, allowing an attacker to retrieve PINs, including the Master PIN, and override standard user permissions. Rently has released a patch as of late June 2026, and no known public exploitation has been reported.

Technical Analysis

CVE-2026-75960 is a CWE-522 (Insufficiently Protected Credentials) flaw in Rently Smart Home systems affecting versions <=20.1.0, allowing a low-privileged, unauthenticated-adjacent attacker (network-based, low complexity) to retrieve sensitive PIN data including the Master PIN, effectively bypassing access control and overriding user permissions. The vulnerability carries a CVSS v3.1 score of 8.1 (High) and CVSS v4.0 score of 8.7 (High), with impact limited to confidentiality and integrity (no availability impact). This is a smart home/IoT access control product rather than a traditional IT or AI infrastructure component, and there is no plausible direct impact to AI agent systems, LLM tool use, or RAG pipelines based on the available data.

Affected Systems

Rently Smart Home versions 20.1.0 and prior (smart lock/access control PIN management system)

Indicators of Compromise

  • None reported; no known public exploitation identified

Remediation Steps

  1. 1

    Apply Vendor Patch

    Ensure Rently Smart Home systems are updated to the patched version released by Rently in late June 2026; no additional user action beyond updating is required.

  2. 2

    Network Segmentation

    Minimize network exposure for smart home/control devices, ensuring they are not directly accessible from the internet.

  3. 3

    Use Secure Remote Access

    When remote access is necessary, use VPNs or other secure remote access methods, keeping them updated to current versions.

  4. 4

    Contact Vendor

    For additional guidance or confirmation of patch status, contact Rently support at support@rently.com.

  5. 5

    Monitor for Suspicious Activity

    Report any suspected malicious activity involving these devices to CISA for tracking and correlation.

CVE / Advisory IDs

CVE-2026-75960

Industries Most Exposed

Commercial FacilitiesCommunicationsInformation Technology

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.