Junglewise Threat Intelligence

CVE-2026-28766: Gardyn Cloud API missing authentication in user account endpoint

CVE-2026-28766 · Severity: critical · CVSS 9.3 · Published 2026-04-03

Technologies: Gardyn Cloud API. Vendors: Gardyn.

Executive brief

A security flaw in the Gardyn Cloud API allowed anyone on the internet to access registered user account information without needing a password. This information included names, addresses, phone numbers, and email addresses of customers using Gardyn Home and Studio indoor gardening systems. While there is no evidence the flaw was exploited by malicious actors, it posed a significant risk to customer privacy and data security.

Technical details

The Gardyn Cloud API suffers from a missing authentication vulnerability (CWE-306) in a specific endpoint. An unauthenticated attacker can access this endpoint over the network to retrieve sensitive user data, including names, physical addresses, phone numbers, and email addresses. The vulnerability affects the Cloud API in versions prior to 2.12.2026. Gardyn has remediated the issue in the cloud environment and recommends users ensure their mobile application is updated to version 2.11.0 or later and device firmware to version 627 or later to ensure full ecosystem security.

Affected products

  • Gardyn Cloud API < 2.12.2026

Timeline

  • 2026-02-24: patched: Original vendor remediation date
  • 2026-04-03: disclosed: Initial NVD publication
  • 2026-07-02: advisory: Latest revision of CISA ICS advisory

References

Related threats