Executive brief
Gardyn Cloud API, which manages smart indoor gardening systems, contains a security flaw where a specific administrative notification endpoint is accessible without authentication. This could allow an unauthorized person to access system notifications or potentially sensitive operational data. While there is no evidence of active exploitation, such a flaw could impact customer privacy or provide insights into system operations.
Technical details
The Gardyn Cloud API suffers from a missing authentication vulnerability (CWE-306) within a specific administrative endpoint used for notifications. An unauthenticated attacker can reach this endpoint over the network without providing valid credentials. Successful exploitation allows the attacker to access information handled by this administrative notification service. The vulnerability was addressed in Cloud API version 2.12.2026. This issue was part of a broader set of vulnerabilities affecting the Gardyn ecosystem, including the Home and Studio firmware and mobile applications.
Affected products
- Gardyn Cloud API before 2.12.2026
Timeline
- 2026-02-24: patched: Initial vendor remediation and internal disclosure
- 2026-04-03: disclosed: Initial NVD publication and ICS-CERT advisory
- 2026-07-02: advisory: Last revision of the CISA ICS advisory