
🔴 Meari IoT Platform Has Unpatched Authorization Flaws Affecting All Versions Meari IoT Cloud Platform OpenAPI Service contains two authorization vulnerabilities (CVE-2026-101104, CVE-2026-96613) that allow authenticated users to manipulate device configurations they do not own and access sensitive data—including device credentials, owner details, and network telemetry—by specifying any device ID. • Affected: All versions of the service; deployed worldwide across commercial facilities and IT infrastructure; company headquartered in China • No fix planned. Meari did not respond to CISA coordination attempts • No known public exploitation reported to date
