Authorization Flaws in Meari IoT Cloud Platform OpenAPI Service (CVE‑2026‑101104, CVE‑2026‑96613) Permit Unauthorized Device Control
What It Is — CISA disclosed two high‑severity authorization defects in Meari’s IoT Cloud Platform OpenAPI Service (CVSS 7.7). Authenticated users can reconfigure any device on the platform, regardless of ownership, and retrieve sensitive data such as device credentials and owner details. No fix has been released and the vendor has not responded.
Exploitability — Publicly disclosed; a valid API credential is sufficient to exploit the flaw, making it readily weaponizable.
Affected Products — Meari IoT Cloud Platform OpenAPI Service, all released versions.
Why It Matters for Trust & Control Assurance
- Directly tests the access‑control control objective: only authorized principals may act on IoT assets.
- Underscores the need for continuous API‑access monitoring and immutable logging as defensible audit evidence.
- Shows that without enforceable authorization, a buyer’s trust in a vendor’s security posture erodes, impacting procurement and compliance reviews.
Recommended Actions
- Inventory every integration that consumes the Meari OpenAPI and isolate its traffic.
- Deploy an API‑gateway or reverse‑proxy that enforces ownership checks before forwarding requests.
- Enable detailed logging of all configuration‑change calls and set alerts for anomalous activity.
- Apply network segmentation to limit the blast radius while a vendor fix is pending.
- Document the control gap and map it to your framework’s access‑control objectives.
Source: CISA Advisory – ICSA‑26‑274‑06