Sceawere

Vulnerability Detail

CVE-2026-96613UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Meari OpenAPI Authorization Bypass

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
7h ago
Vendor
Meari
Product
IoT Cloud Platform OpenAPI Service
Attack Type
CWE-862 Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to access the complete device shadow of any device by specifying its device ID. This vulnerability exposes sensitive information, such as device credentials, owner details, network data, and telemetry, without verifying any relationship between the requester and the target device.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-10-02T16:16:52.490Z",
  "pubdate": "2026-10-02T16:16:52.490Z",
  "executiveSummary": "The Meari IoT Cloud Platform OpenAPI Service is affected by a critical authorization vulnerability that permits authenticated users to access arbitrary device shadows. A device shadow typically contains crucial state information, configurations, and metadata for IoT devices. Due to a deficiency in access control validation, any user with valid authentication credentials can request and retrieve the complete device shadow of any registered device simply by specifying its unique device ID.\nThis vulnerability exposes sensitive information, including device credentials, owner details, network configurations, and telemetry data. The risk implications are severe, as unauthorized access to this data could allow malicious actors to compromise device integrity, track users, or potentially gain unauthorized control over the physical IoT devices. The attack requires minimal exploitation effort, requiring only standard authenticated access and knowledge of target device identifiers, without requiring administrative privileges.",
  "technicalDetails": "The root cause of this vulnerability lies in the failure of the Meari IoT Cloud Platform OpenAPI Service to implement proper Broken Object Level Authorization (BOLA) controls, commonly classified under CWE-285 (Improper Authorization) or CWE-639 (Authorization Bypass Through User-Controlled Key). When a client requests the device shadow of an IoT device via the OpenAPI interface, the application expects a request parameter containing the target device ID. However, the backend service fails to verify whether the authenticated user making the request possesses the authorization or relationship necessary to access that specific device's data.\nThe attack flow proceeds as follows: First, an attacker establishes a valid session with the Meari IoT Cloud Platform OpenAPI Service to obtain legitimate authentication tokens. Second, the attacker constructs an API request targeting the endpoint responsible for retrieving device shadow information. Third, the attacker replaces their own device identifier with the target device ID of an arbitrary user in the request parameters. Fourth, the OpenAPI Service processes the request, validates the attacker's authentication token, but fails to perform an authorization check comparing the requester's identity against the owner or authorized users of the target device ID. Finally, the platform returns the complete device shadow payload to the attacker.\nThe post-exploitation impact of this disclosure is highly critical. The exposed device shadow contains sensitive configuration details, including device credentials, which could allow direct unauthorized access to the device itself. Additionally, the exposure of network data facilitates further network-level attacks, while owner details and real-time telemetry data compromise user privacy and operational security. Because the OpenAPI service is exposed over the network, this vulnerability can be exploited remotely by any authenticated user, regardless of their privilege level."
}
CVE-2026-96613: Meari OpenAPI Authorization Bypass (MEDIUM Severity, CVSS: 6.5) | Sceawere