Authentication Bypass in rust-iot-platform by IoT Ecology
CVE-2026-82452

9.3CRITICAL

Key Information:

Vendor
CVE Published:
29 August 2026

What is CVE-2026-82452?

The rust-iot-platform is vulnerable to an authentication bypass due to insufficient safeguards in its REST API handler signatures. This weakness enables unauthenticated attackers to access unprotected API endpoints, allowing them to create, update, list, retrieve, and delete user accounts without any validation of credentials. This vulnerability poses a significant risk as it could lead to unauthorized modifications and access of sensitive user data.

Affected Version(s)

rust-iot-platform 0 <= 5df942ab6bc46a3bf83dbee8c7970554f92c972d

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Harsh Raj Singhania
.