Skip to content
Threat Feed
high advisory

Authorization Vulnerabilities in Meari IoT Cloud Platform OpenAPI Service

Multiple missing authorization vulnerabilities in the Meari IoT Cloud Platform OpenAPI Service allow authenticated users to access sensitive device data and manipulate configurations for unauthorized devices.

The Meari IoT Cloud Platform OpenAPI Service suffers from critical authorization flaws, identified as CVE-2026-101104 and CVE-2026-96613. Both vulnerabilities stem from improper enforcement of authorization checks (CWE-862). Authenticated users can interact with API endpoints to access the complete device shadow - including credentials, owner details, and telemetry data - for any device by simply specifying its device ID. Furthermore, these flaws permit unauthorized manipulation of device configurations and the triggering of unintended device behaviors. The vulnerabilities affect all versions of the service, and Meari has not provided a remediation plan. Organizations relying on this platform face risks of unauthorized device control and sensitive data exposure, necessitating strict network access controls to mitigate the impact of these unpatchable service vulnerabilities.

Impact

Successful exploitation could lead to unauthorized access to sensitive information including device credentials, network telemetry, and owner data. Additionally, attackers can manipulate device settings, leading to potential service disruption or unauthorized control of IoT assets across commercial and IT sectors globally.

Recommendation

  • Immediately restrict access to the Meari IoT Cloud Platform OpenAPI Service by placing all affected control system networks behind robust firewalls to prevent unauthorized external access.
  • Enforce strict perimeter security and isolate control system networks from general business network traffic.
  • Mandate the use of secure remote access methods such as VPNs for authorized users, while performing regular audits of VPN integrity and connection policies.
  • Conduct an impact assessment to identify all business processes reliant on the Meari IoT Cloud Platform and evaluate alternative, more secure service providers given the lack of planned patches for these vulnerabilities.

Immediate actions

Isolate Meari IoT Cloud Platform endpoints from public internet access

IT Operations 24h

Mitigations

Place affected devices behind firewalls and VPNs

immediate IT Operations

CVE-2026-101104, CVE-2026-96613