Authentication Bypass in SmartLife App via Unverified Email Sign-Up
CVE-2026-86552 Published on September 20, 2026

A vulnerability that skips email ownership verification for account registration in ZTE SmartLife APP
SmartLife app dynamically generates brandnew SmartLife application authentication parameters at runtime. With the acquired SmartLife application authentication credentials, an attacker can directly complete registration using any arbitrary email address via the backend interface /account/person/signup.serv. Email ownership is not verified prior to registration.

NVD

Vulnerability Analysis

CVE-2026-86552 is exploitable with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality, a small impact on integrity and availability.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
LOW
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
LOW
Integrity Impact:
NONE
Availability Impact:
NONE

Weakness Type

Improper Privilege Management

The software does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.


Affected Versions

ZTESW Version ZTE_SL_V2.8.2_ABROAD and prior versions is affected by CVE-2026-86552