Meari OpenAPI flaws expose device credentials, no fix planned
Meari declined CISA coordination twice in a year, leaving operators to isolate platforms they can't patch.
TL;DR
CISA's ICSA-26-274-06 covers two missing-authorization flaws (CWE-862) in Meari's IoT Cloud Platform OpenAPI Service, all versions. An authenticated user can reconfigure devices they don't own (CVE-2026-101104, CVSS 7.7) or pull any device's full shadow, credentials and owner data included, just by supplying its ID (CVE-2026-96613). No fix is planned and Meari didn't answer CISA, so operators have to isolate rather than patch.
CISA published ICSA-26-274-06 on October 1 for Meari's IoT Cloud Platform OpenAPI Service, and the remediation line is the story: no fix planned, vendor unresponsive. Two missing-authorization flaws (CWE-862) affect every version, vers:all/*, letting an authenticated account reach devices it doesn't own.
The first, CVE-2026-101104, lets an authenticated user alter configurations on unowned devices and trigger actions without any ownership check. CISA scores it 7.7 high under CVSS 3.1. The second, CVE-2026-96613, allows a requester to pull a complete device shadow just by supplying its device ID, exposing credentials, owner details, network data, and telemetry. It's 6.5 medium in CVSS 3.1 but 7.1 high in CVSS 4.0. Both are authorization gaps: the platform checks that you're logged in, not whether you own the target.
This is the second time in under a year that Meari has gone silent on CISA. The October 2025 CloudEdge advisory, ICSA-25-294-05 (https://www.cisa.gov/news-events/ics-advisories/icsa-25-294-05), flagged an MQTT wildcard flaw and noted that CloudEdge and its parent Meari Technologies both ignored coordination attempts. Both advisories tell users to contact the vendor. That's a thin mitigation when the vendor won't answer.
No patch path turns compensating controls into the remediation. Segment Meari-based and OEM camera platforms from business networks, remove internet-facing exposure, and force remote access through a current VPN. CISA reports no known public exploitation, but a device-ID authorization flaw is cheap to probe once any account exists. An operator that can't patch should treat every exposed Meari credential as suspect and re-architect access rather than wait for a build.
CISA labels the advisory initial publication with no vendor timeline. Operators should plan for that status to be permanent.
Published ·Deep Fathom