Missing Authentication Vulnerability in the-momentum Open-Wearables Product
CVE-2026-78154
6.9MEDIUM
What is CVE-2026-78154?
A vulnerability exists in the-momentum's open-wearables product, specifically impacting the Public Invitation-Code Redemption Endpoint. This flaw, located in the redeem_invitation_code function, allows for argument manipulation of the code parameter, resulting in missing authentication. As a result, unauthorized remote exploitation could occur, as the functionality does not adequately verify user credentials. Despite early notification of the issue via an issue report, the vendor has yet to issue a response or remediation.
Affected Version(s)
open-wearables 0.6.0
open-wearables 0.6.1
open-wearables 0.6.2
