Executive brief
Gardyn smart home gardening systems were found to have a security flaw where device logs were stored in a publicly accessible cloud storage container. This allowed anyone on the internet to view and list device log files without needing a password or account. While these logs primarily contain technical data, their exposure could lead to the disclosure of sensitive system information or device activity details.
Technical details
This vulnerability is classified as an exposure of sensitive information (CWE-497) due to improper access control on an Azure Blob Storage container. The container used for storing Gardyn device logs was configured to allow public listing, enabling any unauthenticated network-based attacker to enumerate and download log files. This could result in the exposure of system metadata and device-specific operational data. The issue has been remediated through server-side infrastructure updates to the Gardyn Cloud API and automatic firmware updates for Gardyn Home and Studio devices.
Affected products
- Gardyn Gardyn Home Firmware before master.627
- Gardyn Gardyn Studio Firmware before master.627
- Gardyn Gardyn Cloud API before 2.12.2026
Timeline
- 2026-02-24: patched: Original remediation date reported by vendor
- 2026-07-02: advisory: CISA ICSA-26-183-03 published
- 2026-07-03: disclosed: NVD publication date