Sceawere
Vulnerability Detail
CVE-2026-96613UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Meari OpenAPI Authorization Bypass
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 7h ago
- Vendor
- Meari
- Product
- IoT Cloud Platform OpenAPI Service
- Attack Type
- CWE-862 Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to access the complete device shadow of any device by specifying its device ID. This vulnerability exposes sensitive information, such as device credentials, owner details, network data, and telemetry, without verifying any relationship between the requester and the target device.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-10-02T16:16:52.490Z",
"pubdate": "2026-10-02T16:16:52.490Z",
"executiveSummary": "The Meari IoT Cloud Platform OpenAPI Service is affected by a critical authorization vulnerability that permits authenticated users to access arbitrary device shadows. A device shadow typically contains crucial state information, configurations, and metadata for IoT devices. Due to a deficiency in access control validation, any user with valid authentication credentials can request and retrieve the complete device shadow of any registered device simply by specifying its unique device ID.\nThis vulnerability exposes sensitive information, including device credentials, owner details, network configurations, and telemetry data. The risk implications are severe, as unauthorized access to this data could allow malicious actors to compromise device integrity, track users, or potentially gain unauthorized control over the physical IoT devices. The attack requires minimal exploitation effort, requiring only standard authenticated access and knowledge of target device identifiers, without requiring administrative privileges.",
"technicalDetails": "The root cause of this vulnerability lies in the failure of the Meari IoT Cloud Platform OpenAPI Service to implement proper Broken Object Level Authorization (BOLA) controls, commonly classified under CWE-285 (Improper Authorization) or CWE-639 (Authorization Bypass Through User-Controlled Key). When a client requests the device shadow of an IoT device via the OpenAPI interface, the application expects a request parameter containing the target device ID. However, the backend service fails to verify whether the authenticated user making the request possesses the authorization or relationship necessary to access that specific device's data.\nThe attack flow proceeds as follows: First, an attacker establishes a valid session with the Meari IoT Cloud Platform OpenAPI Service to obtain legitimate authentication tokens. Second, the attacker constructs an API request targeting the endpoint responsible for retrieving device shadow information. Third, the attacker replaces their own device identifier with the target device ID of an arbitrary user in the request parameters. Fourth, the OpenAPI Service processes the request, validates the attacker's authentication token, but fails to perform an authorization check comparing the requester's identity against the owner or authorized users of the target device ID. Finally, the platform returns the complete device shadow payload to the attacker.\nThe post-exploitation impact of this disclosure is highly critical. The exposed device shadow contains sensitive configuration details, including device credentials, which could allow direct unauthorized access to the device itself. Additionally, the exposure of network data facilitates further network-level attacks, while owner details and real-time telemetry data compromise user privacy and operational security. Because the OpenAPI service is exposed over the network, this vulnerability can be exploited remotely by any authenticated user, regardless of their privilege level."
}