Critical Authorization Flaws Discovered in Meari IoT Cloud Platform OpenAPI Service
Two CVEs allow authenticated users to manipulate device configurations and access unauthorized device data globally
Key Takeaways
- Two authorization vulnerabilities (CVE-2026-101104 and CVE-2026-96613) affect the Meari IoT Cloud Platform OpenAPI Service.
- CVE-2026-101104 allows authenticated users to manipulate configurations of devices they do not own (CVSS 7.7 HIGH).
- CVE-2026-96613 allows authenticated users to access the complete device shadow of any device, exposing credentials and network data (CVSS 6.5/7.1).
- Both vulnerabilities affect all product versions (vers:all/*).
- Meari has confirmed no fix is planned and did not respond to CISA coordination efforts.
Related Security News
CISA Advises of Sensitive Information Exposure in Johnson Controls EasyIO Neo Series Controllers
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an Industrial Control Systems advisory regarding CVE-2026-64892, a vulnerability in Johnson Controls EasyIO Neo Series EC and CW Controllers that could allow an attacker to gain access to sensitive information. The flaw stems from improper access controls in building automation controllers and impacts four specific firmware versions. Johnson Controls has released fixed firmware versions V3.3b64 (EC) and V3.3b26 (CW) to address the issue.
