Source context: this article examines information published by the source on August 25, 2026. This site’s publication date is shown separately. Check the latest vendor guidance before acting.
What the vulnerability is
CVE-2026-75960 is an insufficiently protected credentials vulnerability (CWE-522) affecting Rently Smart Home systems. The flaw could allow an attacker to retrieve sensitive information, specifically pins including the Master Pin. If successfully exploited, this would enable an actor to override standard user permissions, potentially granting unauthorized administrative control over the affected system.
Exposure and applicability
This vulnerability applies to Rently Smart Home versions 20.1.0 and all prior versions. The systems are deployed in the United States and India, with specific relevance to the Commercial Facilities, Communications, and Information Technology sectors. Asset owners managing building automation or smart home integrations within commercial environments should verify their current versioning.
Remediation priorities
Rently released a patch for this vulnerability in late June. According to the vendor, no manual user action is required to apply the fix. However, from an operational perspective, we analyze the following priorities for facility managers and OT security leads:
- Version Verification: Confirm that the deployed Rently Smart Home software has been updated beyond version 20.1.0.
- Network Isolation: As a general defensive measure to reduce the likelihood of exploitation for any building automation asset, ensure these systems are not directly accessible from the public internet.
- Access Control Review: Place control system networks and remote devices behind firewalls to isolate them from general business networks.
- Secure Remote Access: If remote management is required, utilize secure methods such as Virtual Private Networks (VPNs), ensuring the VPN software itself is current.
How to validate remediation
Because the vendor states that no user action is required for the patch, validation should focus on confirming the current software version. Asset owners can verify the update by checking the system version against the affected range (<=20.1.0). For further confirmation of the update status or to verify if a specific installation has been patched, operators should contact Rently support directly.
Limits and open questions
While the vendor has provided a patch, it remains unclear exactly how the credentials were insufficiently protected or the specific mechanism an attacker would use to retrieve the Master Pin. Additionally, while CISA reports no known public exploitation of this vulnerability at this time, the potential for unauthorized permission overrides represents a significant risk to the physical security and operational integrity of commercial facilities using these systems.
Source and editorial note
Rently Smart Home · Source date: August 25, 2026 · Retrieved August 31, 2026.
Material facts are tied to the cited primary source. Recommendations are independent defensive analysis unless attributed to the source. Confirm consequential decisions against current authoritative guidance.
Request an OT security assessment
Protect the systems your operations depend on.
Discuss your industrial environment, prioritize exposure, and establish evidence that safeguards work.
Request an OT assessment ↗