CRITICAL🇵🇱 Wersja polska

CVE-2026-50084

CVSS 9.6v3.1pub. 2026-06-12upd. 2026-07-09

The Aqara Cloud Production API (open-cn.aqara.com/v3.0/open/api) would authorize any valid developer token for access to any account. This is an instance of "CWE-862: Missing Authorization" with an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N (9.6 Critical). When combined with CVE-2026-50082, CVE-50083, and CVE-50085, this can lead to a fully unauthenticated, remote takeover of affected devices.

🤖 AI Analysis
How it works

The vulnerability results from missing proper authorization verification (CWE-862 — Missing Authorization) in the Aqara cloud API production endpoint. The API accepts any valid developer token and grants access to resources regardless of which account the token actually belongs to. An attacker possessing their own legally obtained developer token can thereby access data and devices assigned to other users. Combined with vulnerabilities CVE-2026-50082, CVE-2026-50083, and CVE-2026-50085, the exploitation chain leads to fully unauthenticated remote device takeover.

Impact

An attacker can gain unauthorized access to any user's account on the Aqara platform, read data, and modify the configuration and state of smart home devices. Exploitation of this vulnerability together with related CVEs may result in complete remote takeover of devices without any prior authorization.

Mitigation & patch

Apply patches available from the manufacturer according to references. It is also recommended to monitor developer token activity for access to unauthorized resources and restrict API token permissions to minimally required scopes.

Who is affected

Aqara Cloud Production API available at open-cn.aqara.com/v3.0/open/api; detailed information about affected versions is provided in the manufacturer's references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
  • Aqara Cloud Production Api

    APP
    Aqara
    2026-04-20
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-50091CRITICAL9.1PL ✓same vendor

Aqara Home Android — zakodowane na stałe klucze kryptograficzne w liblumidevsdk.so

CVE-2026-50086CRITICAL10.0PL ✓same vendor

Aqara IAM/SSO: nieuwierzytelniony oracle AES ujawniający klucz podpisujący

CVE-2026-50083CRITICAL9.1PL ✓same vendor

Aqara IAM/SSO Gateway — zakodowane na stałe dane uwierzytelniające OAuth

CVE-2026-50090CRITICAL9.3PL ✓same vendor

Aqara Cloud OAuth – bypass walidacji redirect URI (open redirect)

CVE-2025-65294CRITICAL9.8PL ✓same vendor

Aqara Hub — nieudokumentowany mechanizm zdalnego wykonania poleceń (RCE)