Junglewise Threat Intelligence

CVE-2026-13768: Gardyn IoT Hub hard-coded privileged key exposure

CVE-2026-13768 · Severity: critical · CVSS 10 · Published 2026-07-03

Technologies: Gardyn Home Firmware, Gardyn Cloud API, Gardyn Studio Firmware. Vendors: Gardyn.

Executive brief

Gardyn smart indoor gardening devices were found to contain hard-coded administrative keys that could allow unauthorized individuals to take control of the systems. An attacker could use these keys to access customer information, view plant photos, or remotely control device functions like lighting and watering. In a worst-case scenario, this could serve as a entry point for an attacker to move onto other devices within a user's home network.

Technical details

The vulnerability is caused by the use of hard-coded credentials (CWE-798) where Gardyn devices expose a privileged 'iothubowner' key for Azure IoT Hub. An unauthenticated attacker with network access to the IoT Hub infrastructure can use this key to invoke Registry Manager functions, retrieving connection strings for all Gardyn Home Kit and Studio devices. Furthermore, the key allows for remote command execution on specific connected devices and potential lateral movement within the victim's local network. Gardyn has remediated the issue by updating their Cloud API and deploying automatic firmware updates to internet-connected devices.

Affected products

  • Gardyn Gardyn Home Firmware < master.627
  • Gardyn Gardyn Studio Firmware < master.627
  • Gardyn Gardyn Cloud API < 2.12.2026

Timeline

  • 2026-02-24: patched: Initial security update published by Gardyn
  • 2026-07-02: advisory: CISA ICSA-26-183-03 published
  • 2026-07-03: disclosed: CVE-2026-13768 published to NVD

References

Related threats