Meari OpenAPI Authorization Gaps Expose Device Controls and Sensitive Data
CISA disclosed two Meari OpenAPI authorization flaws enabling authenticated users to alter device configs and access shadows, with no fix planned.
Illustrative image generated with AI
CISA identifies two cross-account access flaws
CISA has disclosed two authorization vulnerabilities in the Meari IoT Cloud Platform OpenAPI Service that affect interactions between authenticated users and devices outside their ownership scope.
The agency released ICS advisory ICSA-26-274-06 on October 01, 2026. Its product entry lists the affected version as vers:all/* and assigns the status known_affected, covering all versions represented by that designation.
The two vulnerabilities are:
- CVE-2026-101104, which concerns unauthorized changes to device configurations.
- CVE-2026-96613, which allows unauthorized retrieval of a device’s complete shadow.
CISA categorizes both flaws as CWE-862: Missing Authorization. Exploitation requires authentication, but the controls described by the agency do not adequately verify whether the requesting user is authorized to access the selected device.
Meari is headquartered in China, while deployments of the affected service are listed as worldwide. CISA associates the product with the Commercial Facilities and Information Technology sectors.
Authentication succeeds, but device authorization breaks down
The vulnerabilities arise after a user has already authenticated to the service. The central problem is therefore not anonymous access, but inadequate enforcement of permissions at the device level.
With CVE-2026-101104, an authenticated user can manipulate configurations belonging to devices that the user does not own. According to CISA, this could result in modified settings or unintended device behavior.
The vulnerability carries the following ratings:
- CVSS 3.1: 7.7 — HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N - CVSS 4.0: 6.3 — MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N
The CVSS 3.1 vector describes a network-based attack requiring low privileges, low complexity and no action from another user. Its specified direct impact is on integrity rather than confidentiality or availability.
CVE-2026-96613 targets a different OpenAPI function. An authenticated requester can provide a device ID and obtain the complete device shadow for that device. CISA’s description says the request is not adequately checked for a relationship between the user and the target.
Potentially exposed data includes device credentials, owner details, network information and telemetry.
Its ratings are:
- CVSS 3.1: 6.5 — MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N - CVSS 4.0: 7.1 — HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
For this issue, the vectors identify confidentiality as the direct security impact. They do not assign a direct integrity or availability impact to the vulnerable system.
Configuration manipulation and data exposure create separate risks
Although both vulnerabilities share the same missing-authorization classification, their operational consequences differ.
CVE-2026-101104 affects device integrity. A user who is legitimately authenticated to the OpenAPI Service could reach configuration functions for equipment outside that user’s permitted device set. The exact result would depend on the settings and device behaviors available through the service.
CISA’s account supports the possibility of altered configurations and unintended behavior. It does not identify specific device models or enumerate individual actions that could be triggered.
CVE-2026-96613 creates an information-disclosure path instead. Retrieving another device’s complete shadow could reveal details about that device, its owner, its network environment and its telemetry. The disclosed material could also contain device credentials.
The product summary in CISA’s advisory displays CVSS v3 7.7, corresponding to the higher CVSS 3.1 score. The vulnerability-level figures provide the more precise breakdown: 7.7 for CVE-2026-101104 and 6.5 for CVE-2026-96613.
The ordering changes under CVSS 4.0. The configuration vulnerability receives 6.3, while the device-shadow disclosure receives 7.1.
CVE entries remain reserved
The CVE Program records for both identifiers currently show RESERVED rather than published vulnerability descriptions. Consequently, the technical explanations, affected-version scope and severity vectors discussed here come from CISA’s advisory.
The reserved status does not invalidate the identifiers. It means the supplied CVE records do not yet provide their own substantive descriptions.
This distinction limits independent comparison between CISA’s findings and detailed CVE metadata. In particular, the CVE records do not add implementation information or affected product data beyond the identifiers themselves.
CISA credits Gabriel Adams with reporting both vulnerabilities.
At the time it published the advisory, the agency had received no reports of known public exploitation specifically targeting these flaws. That statement is limited to reports received by CISA and to these two vulnerabilities.
The advisory also does not provide vulnerability-specific indicators of compromise or detection signatures.
No vendor correction is planned
CISA assigns No fix planned to both vulnerabilities. The agency says Meari did not respond to its coordination attempts and advises customers using the OpenAPI Service to seek support from the company through https://www.meari.com/en/downLoadCenter.
Operators therefore do not have a vendor update identified by the advisory as a way to correct the missing authorization checks. CISA instead recommends reducing exposure around affected systems and applying defense-in-depth controls.
Its guidance includes:
- Preventing control-system devices and associated systems from being directly reachable from the internet.
- Placing control-system networks and remote devices behind firewalls.
- Separating those environments from business networks.
- Using more secure remote-access methods, including VPNs, when remote connectivity is required.
- Keeping VPN software updated to the latest available version.
- Treating VPN security as dependent on the security of the connected devices as well as the VPN technology itself.
- Conducting impact analysis and risk assessment before deploying defensive changes.
- Following established internal procedures when suspicious activity is identified and reporting relevant findings to CISA.
CISA additionally points organizations toward its industrial-control-system defense-in-depth material and the technical paper identified as ICS-TIP-12-146-01B.
Defenders should focus on ownership boundaries
Because the documented weakness is cross-device authorization, defensive review should concentrate on whether account activity matches expected device ownership and access relationships.
Where suitable logs are available, operators can examine requests involving device IDs outside an account’s normal scope. Reviews can also look for unexpected device-shadow retrievals and configuration activity directed at unrelated equipment.
These are analytical review priorities derived from the behaviors CISA describes. They are not published indicators of exploitation.
Organizations should also inventory where the Meari OpenAPI Service is exposed, identify which accounts can authenticate to it and verify that surrounding network controls restrict unnecessary access. The affected listing is vers:all/*, so CISA’s advisory does not identify an unaffected release branch.
Until Meari provides different remediation guidance, the practical controls available to users are exposure reduction, segmentation, tighter account governance and monitoring of device-level activity.
Sources
This article is an original reworking based on the sources below.
- primary sourceCVE Program
- primary sourceCVE Program
- CISA Advisories




