CRITICAL🇵🇱 Wersja polska

CVE-2026-50086

CVSS 10.0v3.1pub. 2026-06-12upd. 2026-07-09

The Aqara IAM/SSO gateway (gw-builder.aqara.com) exposes bidirectional AES round-trups against the platform's signing key without authentication. This is an instance of "CWE-306: Missing Authentication for Critical Function" and "CWE-327: Use of a Broken or Risky Cryptographic Algorithm," and has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N (7.5 High).

🤖 AI Analysis
How it works

The endpoint gw-builder.aqara.com performs AES encryption and decryption operations (so-called bidirectional AES round-trips) without requiring any authentication. An attacker can repeatedly send their own data to be encrypted or decrypted, creating a cryptographic oracle. The cryptographic algorithm used falls into the broken or risky category (CWE-327), and the lack of an authentication mechanism for this critical function (CWE-306) makes exploitation possible for any user on the Internet.

Impact

An attacker can exploit the oracle to read or reconstruct the Aqara platform signing key, leading to disclosure of confidential data and potential compromise of the integrity of tokens or signatures issued by the IAM/SSO system.

Mitigation & patch

Apply patches available from the vendor according to the references. Until the fix is deployed, it is recommended to block access to the vulnerable endpoint at the firewall level and monitor unauthorized requests to gw-builder.aqara.com.

Who is affected

Aqara IAM/SSO gateway accessible at gw-builder.aqara.com; versions indicated in vendor references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Aqara Iam\/sso Gateway

    APP
    Aqara
    2026-04-20
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-50083CRITICAL9.1PL ✓same product

Aqara IAM/SSO Gateway — zakodowane na stałe dane uwierzytelniające OAuth

CVE-2026-50087HIGH8.2same product

The Aqara IAM/SSO gateway (gw-builder.aqara.com) exhibits a cross-origin request sharing vulnerability, which ...

CVE-2026-50089MEDIUM6.1same product

Brama IAM/SSO Aqara (gw-builder.aqara.com) zawiera podatność open redirect, będącą instancją "CWE-601: URL Red...

CVE-2026-50084CRITICAL9.6PL ✓same vendor

Brak autoryzacji w Aqara Cloud Production API umożliwia przejęcie konta

CVE-2026-50090CRITICAL9.3PL ✓same vendor

Aqara Cloud OAuth – bypass walidacji redirect URI (open redirect)