Authorization Flaw in Meari IoT Cloud Platform OpenAPI Service
CVE-2026-101104
6.3MEDIUM
What is CVE-2026-101104?
The Meari IoT Cloud Platform OpenAPI Service is impacted by an authorization vulnerability that allows authenticated users to manipulate device configurations they do not own. This flaw can lead to unauthorized actions, enabling attackers to change device settings or initiate unintended behaviors without any verification of ownership or permissions.
Affected Version(s)
IoT Cloud Platform OpenAPI Service All verisons
References
CVSS V4
Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Gabriel Adams reported this vulnerability to CISA.
