CISA has warned about two missing-authorization vulnerabilities in the Meari IoT Cloud Platform OpenAPI. The flaws could let an authenticated user cross account boundaries, alter another owner’s device configuration or obtain sensitive device-shadow data.
What an authenticated attacker could access
CVE-2026-101104 concerns authorization checks around device configuration. CVE-2026-96613 affects access to the complete device shadow, which CISA says can include device credentials, owner information, network details and telemetry. The advisory lists a maximum CVSS v3 base score of 7.7 and marks all versions as affected.
The issue is relevant to connected cameras and other cloud-managed devices because the cloud control plane often stores both operational state and credentials. CISA says it is not aware of public exploitation targeting these vulnerabilities.
No vendor fix was available at publication
CISA reports that Meari did not respond to coordination attempts and that no fix was planned when the advisory was released. Users are advised to contact the vendor for information. In the meantime, organizations should review whether affected devices are necessary, isolate them from sensitive networks and monitor cloud-account activity for unexpected configuration changes.
Teams should also rotate exposed credentials where feasible, restrict who can access the management tenant and document an exit plan if risk cannot be reduced. SectechMedia’s video surveillance and imaging coverage explores security considerations for connected camera ecosystems.

Leave a Reply