Junglewise Threat Intelligence

CVE-2026-25197: Gardyn Cloud API authorization bypass via ID modification

CVE-2026-25197 · Severity: critical · CVSS 9.1 · Published 2026-04-03

Technologies: Gardyn Cloud API. Vendors: Gardyn.

Executive brief

Gardyn Cloud API, which manages smart indoor gardening systems, contains a security flaw that allows users to access other customers' profiles. By simply changing an ID number in a web request, an attacker could view private information such as names, addresses, and plant photos, or potentially interfere with the watering and lighting schedules of other users' devices. This issue has been addressed in recent updates to the Gardyn mobile app and device firmware.

Technical details

The Gardyn Cloud API is vulnerable to an Authorization Bypass Through User-Controlled Key (CWE-639), commonly known as Insecure Direct Object Reference (IDOR). A specific API endpoint fails to properly validate that the authenticated user has permission to access the requested resource ID. By modifying the 'id' number in an API call, a remote attacker can pivot to other user profiles. This can lead to the exposure of sensitive demographic information (names, addresses, phone numbers), access to plant photos, and potential remote control of Gardyn Home and Studio devices. The vulnerability is fixed in Cloud API version 2.12.2026, which corresponds with Gardyn Mobile App version 2.11.0 and device firmware version 627.

Affected products

  • Gardyn Cloud API < 2.12.2026

Timeline

  • 2026-02-24: patched: Original vendor remediation date
  • 2026-04-03: disclosed: Initial NVD publication
  • 2026-07-02: advisory: Latest revision of CISA/ICS-CERT advisory

References

Related threats