Skip to content

Executive Summary

The Meari IoT Cloud Platform OpenAPI Service is affected by two authorization flaws, CVE-2026-101104 and CVE-2026-96613, within versions `vers:all/*` of the service. The first vulnerability allows authenticated users to manipulate device configurations for devices they do not own, while the second flaw permits authenticated users to access the complete device shadow of any device by specifying its ID, exposing sensitive data like credentials and network information. Both vulnerabilities are categorized under CWE-862 Missing Authorization. No fixes have been planned by Meari, and they have not responded to coordination attempts from CISA. The platform is deployed worldwide, with the company headquarters located in China, and impacts commercial facilities and information technology sectors.

Facts Only

* Vulnerabilities affect Meari IoT Cloud Platform OpenAPI Service versions `vers:all/*`.
* CVE-2026-101104 allows authenticated users to manipulate device configurations of devices they do not own.
* CVE-2026-96613 allows authenticated users to access the complete device shadow, including credentials, owner details, and network data, for any specified device ID.
* Both vulnerabilities relate to a Missing Authorization flaw (CWE-862).
* Affected software is Meari IoT Cloud Platform OpenAPI Service.
* No fix has been planned by Meari.
* The base severity scores are CVSS 7.7 (HIGH) for the configuration manipulation flaw and CVSS 6.5 (MEDIUM) for the data exposure flaw.
* The vulnerabilities have no known public exploitation reported to CISA at this time.

Full Take

The existence of unpatched authorization flaws in a platform servicing critical infrastructure environments suggests a systemic gap between development practices and operational security, especially when vendors fail to respond to coordination efforts like those from CISA. The fact that vulnerabilities related to access control (CWE-862) have no immediate fix indicates a potential prioritization issue where patching mechanisms or incident response procedures for IoT/Cloud services are lagging behind the threat landscape. The implications for organizations operating in critical infrastructure sectors globally point toward a fragility introduced by relying on proprietary systems without robust, externally validated security lifecycles. The recommended practices from CISA—emphasizing network segmentation and secure remote access—highlight that mitigating such technical flaws must be coupled with broader architectural resilience strategies. This raises questions about the accountability mechanisms for software providers operating across international jurisdictions regarding security responsibilities when vulnerabilities are publicly disclosed but remain unpatched. What level of systemic oversight is required to ensure that vulnerability disclosures automatically trigger mandatory, timely remediation protocols rather than relying on voluntary vendor response?

From the original · CISA Alerts

Summary Successful exploitation of these vulnerabilities could allow attackers to manipulate device configurations, trigger unauthorized behaviors, and access sensitive information such as device credentials, owner details, and network data without proper authorization.
Read the full story at cisa.gov

Sentinel — Human

Confidence

This text exhibits the structure and content typical of a formal vulnerability advisory, likely generated by or heavily based on official security bulletins, indicating human-driven synthesis of technical data rather than pure synthetic generation.

Signals Detected
low severity: Moderate sentence structure variance typical of technical reporting, but the structure is highly formulaic.
low severity: High coherence; standard technical bulletin format. Lacks emotional inflection.
low severity: Strong use of structured tables and standardized legal/policy citations, consistent with official advisories.
low severity: Claims are specific (CVEs, CVSS scores, CISA references) and attribute information to known entities (Meari, CISA).
Human Indicators
The integration of layered advice from multiple authoritative sources (CISA, CWE, vendor notices) suggests a human editorial process synthesizing official data.
The specific focus on post-disclosure mitigation steps and external coordination with CISA points towards real-world incident response reporting.
Meari IoT Cloud Platform OpenAPI Service | Huntaegis