VORANT. Threat Intelligence Research Sign in Create a free account

Meari IoT Cloud Platform flaws unfixed

routine vulnerability infrastructuretechnology

Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.

Two broken authorization bugs in Meari IoT Cloud Platform OpenAPI let authenticated users hijack other owners' devices and steal credentials; no fix planned.

CISA published an advisory for two authorization vulnerabilities in the Meari IoT Cloud Platform OpenAPI Service, affecting all versions. CVE-2026-101104 (CWE-862 Missing Authorization) allows any authenticated user to manipulate configurations and trigger behaviors on devices they do not own, without any ownership or permission check. CVE-2026-96613, also a missing authorization flaw, allows authenticated users to retrieve the complete device shadow of any device by simply specifying its device ID — exposing device credentials, owner details, network data, and telemetry with no relationship verification between requester and target device.

Meari, headquartered in China, did not respond to CISA's coordination attempts, and no fix is planned for either vulnerability. The platform is deployed worldwide and is associated with the Commercial Facilities and Information Technology critical infrastructure sectors. CISA states no known public exploitation of these vulnerabilities has been reported at this time.

Since no patch will be issued, affected organizations should contact Meari directly for support and, in the interim, apply standard network hardening: minimize internet exposure of IoT/control devices, place them behind firewalls isolated from business networks, and use VPNs with up-to-date patching for any required remote access. Given the lack of vendor remediation, defenders using this platform should treat device data and configuration APIs as untrusted and monitor for anomalous cross-device access patterns where feasible.

Mentioned in this report

Vulnerabilities CVE-2026-101104CVE-2026-96613

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-06

What this brief leaves out

This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.

It sits in a corpus of 10,566 reports from 152 sources, 502 of them written in the last seven days, and it grows through the day.

A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.

Create a free account   What it costs