Executive Summary
Facts Only
* Vulnerabilities affect Meari IoT Cloud Platform OpenAPI Service versions `vers:all/*`.
* CVE-2026-101104 allows authenticated users to manipulate device configurations of devices they do not own.
* CVE-2026-96613 allows authenticated users to access the complete device shadow, including credentials, owner details, and network data, for any specified device ID.
* Both vulnerabilities relate to a Missing Authorization flaw (CWE-862).
* Affected software is Meari IoT Cloud Platform OpenAPI Service.
* No fix has been planned by Meari.
* The base severity scores are CVSS 7.7 (HIGH) for the configuration manipulation flaw and CVSS 6.5 (MEDIUM) for the data exposure flaw.
* The vulnerabilities have no known public exploitation reported to CISA at this time.
Full Take
From the original · CISA Alerts
Summary Successful exploitation of these vulnerabilities could allow attackers to manipulate device configurations, trigger unauthorized behaviors, and access sensitive information such as device credentials, owner details, and network data without proper authorization.Read the full story at cisa.gov
Sentinel — Human
This text exhibits the structure and content typical of a formal vulnerability advisory, likely generated by or heavily based on official security bulletins, indicating human-driven synthesis of technical data rather than pure synthetic generation.
