Junglewise Threat Intelligence

CVE-2026-28767: Gardyn Cloud API missing authentication in administrative notification endpoint

CVE-2026-28767 · Severity: medium · CVSS 5.3 · Published 2026-04-03

Technologies: Gardyn Cloud API. Vendors: Gardyn.

Executive brief

Gardyn Cloud API, which manages smart indoor gardening systems, contains a security flaw where a specific administrative notification endpoint is accessible without authentication. This could allow an unauthorized person to access system notifications or potentially sensitive operational data. While there is no evidence of active exploitation, such a flaw could impact customer privacy or provide insights into system operations.

Technical details

The Gardyn Cloud API suffers from a missing authentication vulnerability (CWE-306) within a specific administrative endpoint used for notifications. An unauthenticated attacker can reach this endpoint over the network without providing valid credentials. Successful exploitation allows the attacker to access information handled by this administrative notification service. The vulnerability was addressed in Cloud API version 2.12.2026. This issue was part of a broader set of vulnerabilities affecting the Gardyn ecosystem, including the Home and Studio firmware and mobile applications.

Affected products

  • Gardyn Cloud API before 2.12.2026

Timeline

  • 2026-02-24: patched: Initial vendor remediation and internal disclosure
  • 2026-04-03: disclosed: Initial NVD publication and ICS-CERT advisory
  • 2026-07-02: advisory: Last revision of the CISA ICS advisory

References

Related threats