CVE-2026-80254: Medium severity ShizenBox2 (edge-app) vulnerability
Published Sep 3, 2026
·Updated
Authorization bypass through user-controlled key issue exists in ShizenBox2 (edge-app). If exploited, an attacker who can log in to the product may change the other user's password.
Affected Software
1 affected component
ShizenBox2 (edge-app)
Event History
Sep 3, 2026
CVE Published
via MITRE·08:53 AM
Data Sourced
via MITRE·08:53 AM
DescriptionSeverity
Frequently Asked Questions
1
Who can exploit this issue?
An attacker must be able to log in to ShizenBox2 (edge-app). The vulnerability does not describe an unauthenticated attack path.
2
What could an attacker do after exploiting it?
A logged-in attacker may change another user's password, resulting in unauthorized modification of that user's account credentials.
3
Is user interaction required for exploitation?
No. The supplied CVSS vector indicates that no user interaction is required.