CVE-2026-16581
Received Received - Intake

Inclusion of Sensitive Information in igloohome Smart Lock Mobile App

Vulnerability report for CVE-2026-16581, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-28

Last updated on: 2026-07-28

Assigner: ICS-CERT

Description

In igloohome Smart Lock Mobile App versions 3.2.3 and prior, an Inclusion of Sensitive Information in Source Code vulnerability could allow an unauthorized actor to access functions or backend services that were not sufficiently protected by authentication controls.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-28
Last Modified
2026-07-28
Generated
2026-07-29
AI Q&A
2026-07-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
igloohome smart_lock_mobile_app to 3.2.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-540 Source code on a web server or repository often contains sensitive information and should generally not be accessible to users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the igloohome Smart Lock Mobile App (versions 3.2.3 and prior) involves sensitive information being included in the source code. This could allow unauthorized actors to access backend services or functions that lack proper authentication controls.

Detection Guidance

This vulnerability involves sensitive information exposure in the igloohome Smart Lock Mobile App versions 3.2.3 and prior. Detection requires checking for outdated app versions and analyzing network traffic for unprotected API calls or exposed backend services. Review app source code or decompiled binaries for hardcoded credentials or API endpoints without authentication. Use tools like Wireshark to monitor network requests from the app for unencrypted sensitive data transmission.

Impact Analysis

An attacker could exploit this to access sensitive functions or backend services without proper authentication. This may lead to unauthorized control or data exposure related to the smart lock system.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, potentially violating privacy and security requirements under GDPR, HIPAA, or other regulations. Non-compliance risks include legal penalties and reputational damage.

Mitigation Strategies

Update the igloohome Smart Lock Mobile App to version 3.2.4 or later to address the vulnerability. Ensure strong authentication controls are implemented for backend services and sensitive functions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16581. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart