CRITICAL🇵🇱 Wersja polska

CVE-2026-50083

CVSS 9.1v3.1pub. 2026-06-12upd. 2026-07-09

The Aqara IAM/SSO Gateway (gw-builder.aqara.com) used a hardcoded OAuth client credential, which is an instance of "CWE-798: Use of Hard-coded Credentials." This issue has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N (9.1 Critical). When combined with CVE-2026-50082, CVE-50084, and CVE-50085, this can lead to a fully unauthenticated, remote takeover of affected devices.

🤖 AI Analysis
How it works

The Aqara IAM/SSO gateway software implements fixed, immutable OAuth client credentials (hardcoded credentials) that cannot be changed by the user or administrator. An attacker with knowledge of these credentials can authenticate on behalf of any client without knowing its actual login data. In a chained exploitation scenario with CVE-2026-50082, CVE-2026-50084, and CVE-2026-50085, complete unauthorized remote device takeover is possible.

Impact

An attacker can gain unauthorized access to resources protected by the IAM/SSO gateway, leading to violation of data confidentiality and integrity. In combination with related vulnerabilities, complete remote device takeover is possible without any authentication.

Mitigation & patch

Apply patches available from the manufacturer according to references. It is recommended to monitor official Aqara channels and resources indicated in references (runzero.com/advisories/aqara-hardcoded-oauth-cve-2026-50083) to obtain updates. Until a patch is released, consider restricting network access to the IAM/SSO Gateway service.

Who is affected

Aqara IAM/SSO Gateway (gw-builder.aqara.com) — specific versions indicated in manufacturer references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Aqara Iam\/sso Gateway

    APP
    Aqara
    2026-04-20
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-50086CRITICAL10.0PL ✓same product

Aqara IAM/SSO: nieuwierzytelniony oracle AES ujawniający klucz podpisujący

CVE-2026-50087HIGH8.2same product

The Aqara IAM/SSO gateway (gw-builder.aqara.com) exhibits a cross-origin request sharing vulnerability, which ...

CVE-2026-50089MEDIUM6.1same product

Brama IAM/SSO Aqara (gw-builder.aqara.com) zawiera podatność open redirect, będącą instancją "CWE-601: URL Red...

CVE-2026-50084CRITICAL9.6PL ✓same vendor

Brak autoryzacji w Aqara Cloud Production API umożliwia przejęcie konta

CVE-2026-50090CRITICAL9.3PL ✓same vendor

Aqara Cloud OAuth – bypass walidacji redirect URI (open redirect)