CVE-2026-86554: Email enumeration and account ID leakage vulnerabilities in ZTE SmartLife APP

Published Sep 20, 2026
·
Updated

SmartLife app dynamically generates brand‑new SmartLife application authentication parameters within its runtime process. With the obtained SmartLife application authentication parameters, attackers can directly invoke the backend interface /account/verify.serv to determine whether a target email address is registered for a SmartLife account. If the account exists, the real backend account ID can also be retrieved.

Affected Software

1 affected component
ZTE SmartLife app

Event History

Sep 20, 2026
CVE Published
via MITRE·07:55 AM
Data Sourced
via MITRE·07:55 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker needs to obtain SmartLife application authentication parameters generated by the app at runtime. The provided information does not state that a target user's credentials or interaction are required.

2

What information can an attacker obtain?

The backend interface can be used to determine whether a target email address is registered for a SmartLife account. For registered accounts, it can also return the real backend account ID.

3

How can I tell whether an account may have been exposed?

The available information does not provide logs, indicators, or detection methods. The described exposure concerns account-registration status and backend account IDs queried through the /account/verify.serv interface.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203