CVE-2026-101104
Received Received - Intake

Unauthorized Configuration Manipulation in Meari IoT Cloud Platform

Vulnerability report for CVE-2026-101104, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: ICS-CERT

Description

The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to manipulate the configurations of devices they do not own. This vulnerability enables attackers to perform unauthorized actions, such as altering device settings or triggering unintended behaviors, without verifying ownership or permissions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Meari IoT Cloud Platform OpenAPI Service has an authorization flaw that lets authenticated users change settings for devices they do not own. This allows unauthorized actions like modifying device configurations or triggering behaviors without proper permission checks.

Impact Analysis

Attackers could alter your device settings, cause unintended behaviors, or access sensitive functions without your consent. This may lead to privacy breaches, device malfunctions, or loss of control over your IoT devices.

Compliance Impact

This vulnerability could violate data protection and privacy regulations like GDPR or HIPAA by enabling unauthorized access or control over devices handling sensitive data. Compliance may be compromised due to insufficient access controls and permission verification.

Mitigation Strategies

Immediately review and restrict API access permissions to ensure users can only modify devices they own. Disable or remove unused API endpoints and enforce strict ownership verification for all device configuration changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101104. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart