A notice published on October 1, 2026 describes two authorization flaws in the Meari IoT Cloud OpenAPI Service, affecting all versions. The issues could expose device data and permit unauthorized changes.
A CISA notice published on October 1, 2026 covers two authorization flaws in the Meari IoT Cloud Platform OpenAPI Service. The alert applies to all versions of the service and identifies commercial facilities and information technology as sectors, with worldwide deployment. The feed’s translated text says the company did not respond to CISA’s coordination attempts and no fixes are planned; users are advised to contact Meari for support.
CVE-2026-101104 allows authenticated users to change settings on devices they do not own and trigger unintended behavior. Its CVSS 3.1 score is 7.7, high severity. CVE-2026-96613 allows a requester to retrieve a device’s full representation by specifying its ID, without establishing a relationship to that device, exposing credentials, owner data, network information, and telemetry; its CVSS 3.1 score is 6.5, medium severity. The notice also records CVSS 4.0 scores of 6.3 (medium) and 7.1 (high), respectively. Consult the original CISA advisory and its technical details to verify the scope and check for updates; do not assume an AI platform’s safeguards fix these IoT service flaws.