CISA recommends minimizing network exposure for all control system devices, ensuring they are not accessible from the internet, and locating control system networks and remote devices behind firewalls isolated from business networks. When remote access is required, use VPNs updated to the most current version. Organizations should perform proper impact analysis and risk assessment prior to deploying defensive measures. Users are advised to contact Meari for support as no official fix is planned.
Quick answers
What is CVE-2026-101104?
CISA recommends minimizing network exposure for all control system devices, ensuring they are not accessible from the internet, and locating control system networks and remote devices behind firewalls isolated from business networks. When remote access is required, use VPNs updated to the most current version. Organizations should perform proper impact analysis and risk assessment prior to deploying defensive measures. Users are advised to contact Meari for support as no official fix is planned.
How severe is CVE-2026-101104?
high, CVSS 7.7
Is CVE-2026-101104 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-101104 be mitigated?
CISA recommends minimizing network exposure for all control system devices, ensuring they are not accessible from the internet, and locating control system networks and remote devices behind firewalls isolated from business networks. When remote access is required, use VPNs updated to the most current version. Organizations should perform proper impact analysis and risk assessment prior to deploying defensive measures. Users are advised to contact Meari for support as no official fix is planned.
CVSS
7.7
Vendor
Meari
Published
Oct 2, 2026 · 03:05
Patch
Unknown / not confirmed
Affected products
Meari IoT Cloud Platform OpenAPI Service
Mitigation
CISA recommends minimizing network exposure for all control system devices, ensuring they are not accessible from the internet, and locating control system networks and remote devices behind firewalls isolated from business networks. When remote access is required, use VPNs updated to the most current version. Organizations should perform proper impact analysis and risk assessment prior to deploying defensive measures. Users are advised to contact Meari for support as no official fix is planned.
CISA has issued an industrial control systems advisory warning of two authorization vulnerabilities affecting the Meari IoT Cloud Platform OpenAPI Service. The flaws, tracked as CVE-2026-101104 and CVE-2026-96613, stem from missing authorization checks. CVE-2026-101104 allows authenticated users to manipulate configurations of devices they do not own, while CVE-2026-96613 allows access to the complete device shadow of any device by specifying its ID. Both vulnerabilities affect all product versions (vers:all/*). Notably, Meari has not planned a fix and did not respond to CISA's coordination attempts, leaving users without official remediation.