โ Back to Feed
Meari IoT Cloud Platform OpenAPI Service
CVE-2026-101104CVE-2026-96613
October 1, 2026 ยท CISA (US-CERT) ยท Severity: CRITICAL
CISA disclosed two missing authorization vulnerabilities (CVE-2026-101104, CVE-2026-96613) in Meari IoT Cloud Platform OpenAPI Service. These flaws allow authenticated users to manipulate other devices and access sensitive data. No fix is planned as Meari did not respond. ๐ **Analyst Note:** This is a concerning case of vendor non-responsiveness; organizations using Meari IoT devices should consider isolating them from critical networks and exploring alternative platforms to mitigate the risk of unauthorized access.
Key Takeaways
- Two authorization flaws in Meari IoT Cloud Platform OpenAPI Service allow authenticated users to manipulate configurations of devices they do not own and access complete device shadows.
- Successful exploitation could enable attackers to alter device settings, trigger unintended behaviors, and steal sensitive information like credentials, owner details, and network data.
- Meari did not respond to CISA's coordination attempts and no fix is planned, leaving users of the IoT platform worldwide at risk with no vendor remediation.