# Meari IoT Cloud Platform flaws unfixed

Published: 2026-10-01 · Severity: routine · Sectors: infrastructure, technology
Canonical: https://vorant.io/reports/d4ea581e-df2e-5d2f-98b9-88c7a43ccd26/meari-iot-cloud-platform-flaws-unfixed

> Two broken authorization bugs in Meari IoT Cloud Platform OpenAPI let authenticated users hijack other owners' devices and steal credentials; no fix planned.

CISA published an advisory for two authorization vulnerabilities in the Meari IoT Cloud Platform OpenAPI Service, affecting all versions. CVE-2026-101104 (CWE-862 Missing Authorization) allows any authenticated user to manipulate configurations and trigger behaviors on devices they do not own, without any ownership or permission check. CVE-2026-96613, also a missing authorization flaw, allows authenticated users to retrieve the complete device shadow of any device by simply specifying its device ID — exposing device credentials, owner details, network data, and telemetry with no relationship verification between requester and target device.

Meari, headquartered in China, did not respond to CISA's coordination attempts, and no fix is planned for either vulnerability. The platform is deployed worldwide and is associated with the Commercial Facilities and Information Technology critical infrastructure sectors. CISA states no known public exploitation of these vulnerabilities has been reported at this time.

Since no patch will be issued, affected organizations should contact Meari directly for support and, in the interim, apply standard network hardening: minimize internet exposure of IoT/control devices, place them behind firewalls isolated from business networks, and use VPNs with up-to-date patching for any required remote access. Given the lack of vendor remediation, defenders using this platform should treat device data and configuration APIs as untrusted and monitor for anomalous cross-device access patterns where feasible.

## Mentioned in this report

- Vulnerabilities: CVE-2026-101104, CVE-2026-96613

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-06

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/d4ea581e-df2e-5d2f-98b9-88c7a43ccd26/meari-iot-cloud-platform-flaws-unfixed.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
