mygardyn has 5 CVEs on record. The busiest recent month was April 2026 with 5. The median CVSS is 7.5 (high), with 2 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-306 (3).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.5
- Publish → KEV
- —
- Last 90 days
- 0 prev 5
Worst active — by depth score
CVE-2026-28766Critical· 9.3A specific endpoint exposes all user account information for registered Gardyn users without requiring authentication.63CVE-2026-25197Critical· 9.1A specific endpoint allows authenticated users to pivot to other user profiles by modifying the id number in the API call.62CVE-2026-32646High· 7.5A specific administrative endpoint is accessible without proper authentication, exposing device management functions.53CVE-2026-32662Medium· 5.3Development and test API endpoints are present that mirror production functionality.41CVE-2026-28767Medium· 5.3A specific administrative endpoint notifications is accessible without proper authentication.41
mygardyn vulnerabilities
CVEs affecting mygardyn, newest first. Open any entry for full detail, references, and exploit status.
5 CVEsRSS
CVE-2026-32662Medium· 5.3PoCDevelopment and test API endpoints are present that mirror production functionality.
Development and test API endpoints are present that mirror production functionality.
CVE-2026-32646High· 7.5PoCA specific administrative endpoint is accessible without proper authentication, exposing device management functions.
A specific administrative endpoint is accessible without proper authentication, exposing device management functions.
CVE-2026-28767Medium· 5.3PoCA specific administrative endpoint notifications is accessible without proper authentication.
A specific administrative endpoint notifications is accessible without proper authentication.
CVE-2026-28766Critical· 9.3PoCA specific endpoint exposes all user account information for registered Gardyn users without requiring authentication.
A specific endpoint exposes all user account information for registered Gardyn users without requiring authentication.
CVE-2026-25197Critical· 9.1PoCA specific endpoint allows authenticated users to pivot to other user profiles by modifying the id number in the API call.
A specific endpoint allows authenticated users to pivot to other user profiles by modifying the id number in the API call.