CISA flags Gardyn IoT Hub flaws at CVSS 10
Hard-coded cloud keys and public device logs are table-stakes failures when the device manages food and agriculture operations.
TL;DR
CISA published ICSA-26-183-03 for three Gardyn IoT Hub vulnerabilities affecting Home and Studio firmware below master.627 and Cloud API below 2.12.2026. The worst, CVE-2026-13768, carries CVSS 10 and exposes a privileged iothubowner key that can return connection information, execute commands on connected devices, and support network pivoting. Gardyn says deployed IoT Hub infrastructure has been updated, but customers must connect devices for automatic firmware updates and update the mobile app.
CISA’s advisory is a patch-now item for any organization managing Gardyn devices in food and agriculture environments, and a procurement lesson for everyone else buying internet-connected operational technology. CVE-2026-13768 exposes a privileged iothubowner key, letting an unauthenticated attacker invoke IoT Hub Registry Manager functions, retrieve connection information for Gardyn Home Kit and Studio devices, execute arbitrary commands on a connected device, and potentially pivot to other devices on the user’s network. CISA rates it CVSS v3 10.
The two companion flaws are less severe but still ugly. CVE-2026-55726 made the Azure Blob Storage container used for Gardyn device logs publicly listable without authentication, exposing any available device log file. CVE-2026-54477 says the admin panel lacks standard security headers, enabling clickjacking and cross-site scripting. The affected products are Gardyn Home Firmware and Gardyn Studio Firmware before master.627, plus Gardyn Cloud API before 2.12.2026.
Gardyn says the deployed IoT Hub infrastructure has been updated. That only solves part of the operational problem. CISA says users should make sure devices have internet connectivity so they can automatically download firmware updates, and that unconnected devices will update only when configured with a working connection. Customers should also update the Gardyn mobile application and verify current app and Home firmware versions inside the app.
For contractors, managed service providers, and assessors supporting agricultural, food production, or adjacent operational environments, the Monday work is basic and immediate: inventory Gardyn devices, confirm firmware and app versions, review logs for abnormal device access, and avoid assuming the cloud-side fix cleaned up every customer-side exposure. CISA says it has no reports of public exploitation targeting these vulnerabilities. That is useful, but it is not a compensating control.
Published ·Deep Fathom