VYPR
Critical severity10.0NVD Advisory· Published Jun 12, 2026· Updated Jun 12, 2026

CVE-2026-50086

CVE-2026-50086

Description

The Aqara IAM/SSO gateway exposes unauthenticated AES encrypt/decrypt endpoints, allowing attackers to decrypt and forge ciphertexts under the platform's signing key.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

The Aqara IAM/SSO gateway exposes unauthenticated AES encrypt/decrypt endpoints, allowing attackers to decrypt and forge ciphertexts under the platform's signing key.

Vulnerability

The Aqara IAM/SSO gateway at gw-builder.aqara.com exposes two unauthenticated endpoints: POST /iam/oauthToken/aseEncrypt and POST /iam/oauthToken/aseDecrypt. These endpoints perform AES encryption and decryption using the platform's signing key in ECB mode, as confirmed by identical 16-byte plaintext blocks producing identical ciphertext blocks [1][2]. No authentication is required to access these endpoints, constituting CWE-306 and CWE-327. The vulnerability affects all versions of the gateway prior to the vendor's fix on April 20, 2026 [2].

Exploitation

An attacker with network access to the gateway can send arbitrary plaintext to the encrypt endpoint to obtain the corresponding ciphertext under the platform's key, or send arbitrary ciphertext to the decrypt endpoint to recover the plaintext. Known ciphertext samples (e.g., admino3icZFqAnrbLNYAvMjKpZA==) were observed and successfully round-tripped [2]. Because ECB mode is used, the attacker can also manipulate ciphertext blocks to forge valid encrypted payloads. No authentication, user interaction, or special privileges are required.

Impact

Successful exploitation allows an attacker to decrypt any captured ciphertext (such as cookies, tokens, or structured payloads) that was encrypted with the platform's signing key, and to forge new ciphertexts that will be accepted by the system. This leads to information disclosure of sensitive data and potential privilege escalation by forging authentication tokens. The vulnerability is rated CVSS 7.5 (High) due to network attack vector, low complexity, and no privileges required [2].

Mitigation

The vendor (Aqara) remediated this vulnerability on April 20, 2026, as stated in the disclosure timeline [2]. No workarounds are documented. Users should ensure their gateway instances are updated to the patched version. The vulnerability is part of a chain of ten CVEs disclosed on June 11, 2026 [1].

AI Insight generated on Jun 12, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

0

No linked articles in our index yet.