The Aqara Cloud Production API (open-cn.aqara.com/v3.0/open/api) would authorize any valid developer token for access to any account. This is an instance of "CWE-862: Missing Authorization" with an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N (9.6 Critical). When combined with CVE-2026-50082, CVE-50083, and CVE-50085, this can lead to a fully unauthenticated, remote takeover of affected devices.
The vulnerability results from missing proper authorization verification (CWE-862 — Missing Authorization) in the Aqara cloud API production endpoint. The API accepts any valid developer token and grants access to resources regardless of which account the token actually belongs to. An attacker possessing their own legally obtained developer token can thereby access data and devices assigned to other users. Combined with vulnerabilities CVE-2026-50082, CVE-2026-50083, and CVE-2026-50085, the exploitation chain leads to fully unauthenticated remote device takeover.
An attacker can gain unauthorized access to any user's account on the Aqara platform, read data, and modify the configuration and state of smart home devices. Exploitation of this vulnerability together with related CVEs may result in complete remote takeover of devices without any prior authorization.
Apply patches available from the manufacturer according to references. It is also recommended to monitor developer token activity for access to unauthorized resources and restrict API token permissions to minimally required scopes.
Aqara Cloud Production API available at open-cn.aqara.com/v3.0/open/api; detailed information about affected versions is provided in the manufacturer's references
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:NAqara Cloud Production Api
APPAqara2026-04-20
Related vulnerabilities
Aqara Home Android — zakodowane na stałe klucze kryptograficzne w liblumidevsdk.so
Aqara IAM/SSO: nieuwierzytelniony oracle AES ujawniający klucz podpisujący
Aqara IAM/SSO Gateway — zakodowane na stałe dane uwierzytelniające OAuth
Aqara Cloud OAuth – bypass walidacji redirect URI (open redirect)
Aqara Hub — nieudokumentowany mechanizm zdalnego wykonania poleceń (RCE)