Authorization Flaw in Meari IoT Cloud Platform OpenAPI Service
CVE-2026-101104

6.3MEDIUM

Key Information:

Vendor

Meari

Vendor
CVE Published:
2 October 2026

What is CVE-2026-101104?

The Meari IoT Cloud Platform OpenAPI Service is impacted by an authorization vulnerability that allows authenticated users to manipulate device configurations they do not own. This flaw can lead to unauthorized actions, enabling attackers to change device settings or initiate unintended behaviors without any verification of ownership or permissions.

Affected Version(s)

IoT Cloud Platform OpenAPI Service All verisons

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Gabriel Adams reported this vulnerability to CISA.
.