Loading market data...
← Back to CVE feed

CVE-2026-101104

HIGH CVSS 7.7 View on NVD ↗

Description

The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to manipulate the configurations of devices they do not own. This vulnerability enables attackers to perform unauthorized actions, such as altering device settings or triggering unintended behaviors, without verifying ownership or permissions.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
Published: Oct 02, 2026 16:16 UTC Modified: Oct 02, 2026 18:47 UTC