The Aqara IAM/SSO Gateway (gw-builder.aqara.com) used a hardcoded OAuth client credential, which is an instance of "CWE-798: Use of Hard-coded Credentials." This issue has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N (9.1 Critical). When combined with CVE-2026-50082, CVE-50084, and CVE-50085, this can lead to a fully unauthenticated, remote takeover of affected devices.
The Aqara IAM/SSO gateway software implements fixed, immutable OAuth client credentials (hardcoded credentials) that cannot be changed by the user or administrator. An attacker with knowledge of these credentials can authenticate on behalf of any client without knowing its actual login data. In a chained exploitation scenario with CVE-2026-50082, CVE-2026-50084, and CVE-2026-50085, complete unauthorized remote device takeover is possible.
An attacker can gain unauthorized access to resources protected by the IAM/SSO gateway, leading to violation of data confidentiality and integrity. In combination with related vulnerabilities, complete remote device takeover is possible without any authentication.
Apply patches available from the manufacturer according to references. It is recommended to monitor official Aqara channels and resources indicated in references (runzero.com/advisories/aqara-hardcoded-oauth-cve-2026-50083) to obtain updates. Until a patch is released, consider restricting network access to the IAM/SSO Gateway service.
Aqara IAM/SSO Gateway (gw-builder.aqara.com) — specific versions indicated in manufacturer references
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NAqara Iam\/sso Gateway
APPAqara2026-04-20
Related vulnerabilities
Aqara IAM/SSO: nieuwierzytelniony oracle AES ujawniający klucz podpisujący
The Aqara IAM/SSO gateway (gw-builder.aqara.com) exhibits a cross-origin request sharing vulnerability, which ...
Brama IAM/SSO Aqara (gw-builder.aqara.com) zawiera podatność open redirect, będącą instancją "CWE-601: URL Red...
Brak autoryzacji w Aqara Cloud Production API umożliwia przejęcie konta
Aqara Cloud OAuth – bypass walidacji redirect URI (open redirect)