Executive brief
Meari's IoT Cloud Platform OpenAPI Service, which manages connected IoT devices and their configurations, contains authorization flaws that allow attackers to bypass access controls. An attacker can manipulate device settings, access sensitive information like device credentials and owner details, and trigger unauthorized device behaviors without proper authentication.
Technical details
The OpenAPI Service implements missing authorization controls on API endpoints, allowing unauthenticated or unauthorized requests to modify device configurations and retrieve sensitive data. The vulnerability affects all versions of the service and can be exploited remotely over the network without user interaction or prior authentication.
Affected products
- Meari IoT Cloud Platform OpenAPI Service all
CVE identifiers
- CVE-2026-96613
- CVE-2026-101104
Timeline
- 2026-10-01: disclosed