Authorization Flaw in Meari IoT Cloud Platform Exposes Sensitive Device Information
CVE-2026-96613
7.1HIGH
What is CVE-2026-96613?
The Meari IoT Cloud Platform's OpenAPI Service has a significant authorization flaw that permits authenticated users to access the complete device shadow of any device by simply providing its device ID. This vulnerability compromises sensitive information, including device credentials, owner details, network data, and telemetry, due to a lack of necessary verification between the requester and the target device. As a result, unauthorized access to this critical data can lead to serious security implications and privacy breaches.
Affected Version(s)
IoT Cloud Platform OpenAPI Service All verisons
References
CVSS V4
Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Gabriel Adams reported this vulnerability to CISA.
