Authorization Flaw in Meari IoT Cloud Platform Exposes Sensitive Device Information
CVE-2026-96613

7.1HIGH

Key Information:

Vendor

Meari

Vendor
CVE Published:
2 October 2026

What is CVE-2026-96613?

The Meari IoT Cloud Platform's OpenAPI Service has a significant authorization flaw that permits authenticated users to access the complete device shadow of any device by simply providing its device ID. This vulnerability compromises sensitive information, including device credentials, owner details, network data, and telemetry, due to a lack of necessary verification between the requester and the target device. As a result, unauthorized access to this critical data can lead to serious security implications and privacy breaches.

Affected Version(s)

IoT Cloud Platform OpenAPI Service All verisons

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Gabriel Adams reported this vulnerability to CISA.
.