{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CVE-2026-101104",
"assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
"state": "PUBLISHED",
"assignerShortName": "icscert",
"dateReserved": "2026-09-29T16:11:36.322Z",
"datePublished": "2026-10-02T15:58:21.626Z",
"dateUpdated": "2026-10-03T15:52:56.225Z"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
"shortName": "icscert",
"dateUpdated": "2026-10-02T15:58:21.626Z"
},
"title": "Missing Authorization in Meari IoT Cloud Platform OpenAPI Service",
"problemTypes": [
{
"descriptions": [
{
"lang": "en",
"cweId": "CWE-862",
"description": "CWE-862 Missing Authorization",
"type": "CWE"
}
]
}
],
"affected": [
{
"vendor": "Meari",
"product": "IoT Cloud Platform OpenAPI Service",
"versions": [
{
"status": "affected",
"version": "All verisons",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
}
],
"descriptions": [
{
"lang": "en",
"value": "The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to manipulate the configurations of devices they do not own. This vulnerability enables attackers to perform unauthorized actions, such as altering device settings or triggering unintended behaviors, without verifying ownership or permissions.",
"supportingMedia": [
{
"type": "text/html",
"base64": false,
"value": "The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to manipulate the configurations of devices they do not own. This vulnerability enables attackers to perform unauthorized actions, such as altering device settings or triggering unintended behaviors, without verifying ownership or permissions.
"
}
]
}
],
"references": [
{
"url": "https://www.meari.com/en/downLoadCenter"
},
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-06"
},
{
"url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-274-06.json"
}
],
"metrics": [
{
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
],
"cvssV4_0": {
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"vulnConfidentialityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"subIntegrityImpact": "HIGH",
"vulnAvailabilityImpact": "NONE",
"subAvailabilityImpact": "NONE",
"exploitMaturity": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"valueDensity": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"version": "4.0",
"baseSeverity": "MEDIUM",
"baseScore": 6.3,
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N"
}
},
{
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
],
"cvssV3_1": {
"version": "3.1",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "CHANGED",
"confidentialityImpact": "NONE",
"integrityImpact": "HIGH",
"availabilityImpact": "NONE",
"baseSeverity": "HIGH",
"baseScore": 7.7,
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N"
}
}
],
"workarounds": [
{
"lang": "en",
"value": "Meari did not respond to CISA's coordination attempts. IoT Cloud Platform OpenAPI users are advised to contact Meari for support https://www.meari.com/en/downLoadCenter .",
"supportingMedia": [
{
"type": "text/html",
"base64": false,
"value": "Meari did not respond to CISA's coordination attempts. IoT Cloud Platform OpenAPI users are advised to contact Meari for support https://www.meari.com/en/downLoadCenter."
}
]
}
],
"credits": [
{
"lang": "en",
"value": "Gabriel Adams reported this vulnerability to CISA.",
"type": "reporter"
}
],
"source": {
"advisory": "ICSA-26-274-06",
"discovery": "EXTERNAL"
},
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
},
"adp": [
{
"metrics": [
{
"other": {
"type": "ssvc",
"content": {
"id": "CVE-2026-101104",
"role": "CISA Coordinator",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-10-03T15:48:40.528236Z"
}
}
}
],
"title": "CISA ADP Vulnrichment",
"providerMetadata": {
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP",
"dateUpdated": "2026-10-03T15:52:56.225Z"
}
}
]
}
}