Executive brief
A security flaw in the Gardyn Cloud API allowed anyone on the internet to access registered user account information without needing a password. This information included names, addresses, phone numbers, and email addresses of customers using Gardyn Home and Studio indoor gardening systems. While there is no evidence the flaw was exploited by malicious actors, it posed a significant risk to customer privacy and data security.
Technical details
The Gardyn Cloud API suffers from a missing authentication vulnerability (CWE-306) in a specific endpoint. An unauthenticated attacker can access this endpoint over the network to retrieve sensitive user data, including names, physical addresses, phone numbers, and email addresses. The vulnerability affects the Cloud API in versions prior to 2.12.2026. Gardyn has remediated the issue in the cloud environment and recommends users ensure their mobile application is updated to version 2.11.0 or later and device firmware to version 627 or later to ensure full ecosystem security.
Affected products
- Gardyn Cloud API < 2.12.2026
Timeline
- 2026-02-24: patched: Original vendor remediation date
- 2026-04-03: disclosed: Initial NVD publication
- 2026-07-02: advisory: Latest revision of CISA ICS advisory