โ† Back to Feed

Meari IoT Cloud Platform OpenAPI Service

CVE-2026-101104CVE-2026-96613

October 1, 2026 ยท CISA (US-CERT) ยท Severity: CRITICAL

CISA disclosed two missing authorization vulnerabilities (CVE-2026-101104, CVE-2026-96613) in Meari IoT Cloud Platform OpenAPI Service. These flaws allow authenticated users to manipulate other devices and access sensitive data. No fix is planned as Meari did not respond. ๐Ÿ“Œ **Analyst Note:** This is a concerning case of vendor non-responsiveness; organizations using Meari IoT devices should consider isolating them from critical networks and exploring alternative platforms to mitigate the risk of unauthorized access.

Key Takeaways

  • Two authorization flaws in Meari IoT Cloud Platform OpenAPI Service allow authenticated users to manipulate configurations of devices they do not own and access complete device shadows.
  • Successful exploitation could enable attackers to alter device settings, trigger unintended behaviors, and steal sensitive information like credentials, owner details, and network data.
  • Meari did not respond to CISA's coordination attempts and no fix is planned, leaving users of the IoT platform worldwide at risk with no vendor remediation.
โ˜• Buy a Coffee