{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/meari/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Meari IoT Cloud Platform OpenAPI Service (all versions)"],"_cs_severities":["high"],"_cs_tags":["iot","vulnerability","cloud","authorization"],"_cs_type":"advisory","_cs_vendors":["Meari"],"content_html":"\u003cp\u003eThe Meari IoT Cloud Platform OpenAPI Service suffers from critical authorization flaws, identified as CVE-2026-101104 and CVE-2026-96613. Both vulnerabilities stem from improper enforcement of authorization checks (CWE-862). Authenticated users can interact with API endpoints to access the complete device shadow - including credentials, owner details, and telemetry data - for any device by simply specifying its device ID. Furthermore, these flaws permit unauthorized manipulation of device configurations and the triggering of unintended device behaviors. The vulnerabilities affect all versions of the service, and Meari has not provided a remediation plan. Organizations relying on this platform face risks of unauthorized device control and sensitive data exposure, necessitating strict network access controls to mitigate the impact of these unpatchable service vulnerabilities.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation could lead to unauthorized access to sensitive information including device credentials, network telemetry, and owner data. Additionally, attackers can manipulate device settings, leading to potential service disruption or unauthorized control of IoT assets across commercial and IT sectors globally.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately restrict access to the Meari IoT Cloud Platform OpenAPI Service by placing all affected control system networks behind robust firewalls to prevent unauthorized external access.\u003c/li\u003e\n\u003cli\u003eEnforce strict perimeter security and isolate control system networks from general business network traffic.\u003c/li\u003e\n\u003cli\u003eMandate the use of secure remote access methods such as VPNs for authorized users, while performing regular audits of VPN integrity and connection policies.\u003c/li\u003e\n\u003cli\u003eConduct an impact assessment to identify all business processes reliant on the Meari IoT Cloud Platform and evaluate alternative, more secure service providers given the lack of planned patches for these vulnerabilities.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-01T17:06:25Z","date_published":"2026-10-01T17:06:25Z","id":"https://feed.craftedsignal.io/briefs/2026-10-meari-iot-auth-flaws/","summary":"Multiple missing authorization vulnerabilities in the Meari IoT Cloud Platform OpenAPI Service allow authenticated users to access sensitive device data and manipulate configurations for unauthorized devices.","title":"Authorization Vulnerabilities in Meari IoT Cloud Platform OpenAPI Service","url":"https://feed.craftedsignal.io/briefs/2026-10-meari-iot-auth-flaws/"}],"language":"en","title":"CraftedSignal Threat Feed - Meari","version":"https://jsonfeed.org/version/1.1"}