OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-101104

HIGH · CVSS 7.7 EPSS 0.27% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-02 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The Meari IoT Cloud Platform OpenAPI Service has an authorization flaw that permits authenticated users to modify configurations of devices they do not own, leading to unauthorized actions like changing device settings or causing unintended behaviors. This vulnerability poses a significant risk to device integrity and user privacy. Organizations utilizing the Meari IoT platform should prioritize addressing this issue to safeguard their devices and data.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-101104
Severity
HIGH
CVSS
7.7
EPSS
0.27%

Original NVD Description

The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to manipulate the configurations of devices they do not own. This vulnerability enables attackers to perform unauthorized actions, such as altering device settings or triggering unintended behaviors, without verifying ownership or permissions.