{"id":"CVE-2026-101104","title":"The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to manipulate the configurations of devices they do not own","summary":"The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to manipulate the configurations of devices they do not own. This vulnerability enables attackers to perform unauthorized…","severity":"high","cvss":7.7,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N","cwe":["CWE-862"],"vendor":"Meari","product":"IoT Cloud Platform OpenAPI Service","affected":["iot_cloud_platform_openapi_service All verisons"],"published":"2026-10-02","updated":"2026-10-02","sourceUpdated":"2026-10-02T16:16:42.883","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-101104","references":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-274-06.json","label":"ics-cert@hq.dhs.gov"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-06","label":"ics-cert@hq.dhs.gov"},{"url":"https://www.meari.com/en/downLoadCenter","label":"ics-cert@hq.dhs.gov"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-02T16:22:59.521Z","slug":"CVE-2026-101104","body":"## Overview\n\nThe Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to manipulate the configurations of devices they do not own. This vulnerability enables attackers to perform unauthorized actions, such as altering device settings or triggering unintended behaviors, without verifying ownership or permissions.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":42.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}