Junglewise Threat Intelligence

CVE-2026-96613: Meari IoT Cloud Platform OpenAPI Service missing authorization

CVE-2026-96613 · Severity: high · Published 2026-10-01

Vendors: Meari.

Executive brief

Meari's IoT Cloud Platform OpenAPI Service, which manages connected IoT devices and their configurations, contains authorization flaws that allow attackers to bypass access controls. An attacker can manipulate device settings, access sensitive information like device credentials and owner details, and trigger unauthorized device behaviors without proper authentication.

Technical details

The OpenAPI Service implements missing authorization controls on API endpoints, allowing unauthenticated or unauthorized requests to modify device configurations and retrieve sensitive data. The vulnerability affects all versions of the service and can be exploited remotely over the network without user interaction or prior authentication.

Affected products

  • Meari IoT Cloud Platform OpenAPI Service all

CVE identifiers

  • CVE-2026-96613
  • CVE-2026-101104

Timeline

  • 2026-10-01: disclosed