cloud_api vulnerabilities
CVEs whose affected-version data names the cloud_api package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
5 CVEsRSS
CVE-2026-32662Medium· 5.3PoCDevelopment and test API endpoints are present that mirror production functionality.
Development and test API endpoints are present that mirror production functionality.
▾ Twilightmygardyn · cloud_apiEPSS 0.32%via NVD
CVE-2026-32646High· 7.5PoCA specific administrative endpoint is accessible without proper authentication, exposing device management functions.
A specific administrative endpoint is accessible without proper authentication, exposing device management functions.
▾ Midnightmygardyn · cloud_apiEPSS 0.49%via NVD
CVE-2026-28767Medium· 5.3PoCA specific administrative endpoint notifications is accessible without proper authentication.
A specific administrative endpoint notifications is accessible without proper authentication.
▾ Twilightmygardyn · cloud_apiEPSS 0.38%via NVD
CVE-2026-28766Critical· 9.3PoCA specific endpoint exposes all user account information for registered Gardyn users without requiring authentication.
A specific endpoint exposes all user account information for registered Gardyn users without requiring authentication.
▾ Abyssalmygardyn · cloud_apiEPSS 0.44%via NVD
CVE-2026-25197Critical· 9.1PoCA specific endpoint allows authenticated users to pivot to other user profiles by modifying the id number in the API call.
A specific endpoint allows authenticated users to pivot to other user profiles by modifying the id number in the API call.
▾ Abyssalmygardyn · cloud_apiEPSS 0.29%via NVD