VYPR
advisoryPublished Oct 1, 2026· 1 source

Critical Authorization Flaws in Meari IoT Cloud Platform Expose Device Data

CISA has identified two critical authorization vulnerabilities in Meari's IoT Cloud Platform OpenAPI Service, allowing unauthorized manipulation of device configurations and access to sensitive data.

CISA has issued a critical advisory detailing two severe authorization flaws within the Meari IoT Cloud Platform OpenAPI Service. These vulnerabilities, identified as CVE-2026-101104 and CVE-2026-96613, pose a significant risk to users by enabling authenticated attackers to gain unauthorized control over devices and access sensitive information.

The first vulnerability, CVE-2026-101104, is a missing authorization flaw that permits authenticated users to manipulate the configurations of devices they do not own. This could lead to attackers altering device settings, triggering unintended behaviors, or disrupting normal operations without any form of ownership verification. The CVSS v3.1 score for this vulnerability is a high 7.7, indicating a significant security risk.

Compounding the issue, CVE-2026-96613 is another authorization flaw that allows authenticated users to access the complete "device shadow" of any device simply by providing its device ID. This grants attackers access to a wealth of sensitive data, including device credentials, owner details, network information, and telemetry, without any authorization checks. This vulnerability is rated with a CVSS v3.1 score of 6.5, classifying it as medium severity but still posing a considerable threat.

These vulnerabilities affect all versions of the Meari IoT Cloud Platform OpenAPI Service. The advisory highlights that Meari did not respond to CISA's coordination attempts to address these issues. Consequently, no fix is currently planned, and users are advised to contact Meari directly for support, though no specific remediation guidance beyond contacting the vendor has been provided.

The potential impact of these flaws is substantial, particularly for critical infrastructure sectors such as Commercial Facilities and Information Technology, where these devices may be deployed worldwide. Attackers could leverage these vulnerabilities to compromise device integrity, steal sensitive credentials, and gain unauthorized access to network data, potentially leading to widespread disruption and data breaches.

CISA recommends that organizations minimize network exposure for all control system devices and systems, ensuring they are not accessible from the internet. Networks should be protected behind firewalls and isolated from business networks. When remote access is necessary, more secure methods like VPNs should be employed, ensuring they are kept up-to-date. Organizations are urged to perform thorough impact analyses and risk assessments before implementing any defensive measures.

While no known public exploitation has been reported to CISA at this time, the critical nature of these vulnerabilities necessitates immediate attention from users of the Meari IoT Cloud Platform OpenAPI Service. The lack of a vendor response and planned fix underscores the importance of proactive security measures and risk mitigation strategies for affected organizations.

This advisory serves as a stark reminder of the ongoing security challenges within the Internet of Things (IoT) ecosystem, particularly concerning cloud-connected devices and the potential for critical infrastructure to be exposed through insecure platform services. The absence of vendor engagement in addressing these severe flaws leaves users in a precarious position, emphasizing the need for robust vendor security practices and supply chain risk management.

Synthesized by Vypr AI