
[CVE-2026-28766: CRITICAL] A specific endpoint exposes all user account information for registered Gardyn users without requiring authentication.#cve,CVE-2026-28766,#cybersecurity https://cvefind.com/CVE-2026-28766
Post summary
The tweet announces a critical information‑disclosure flaw (CVE‑2026‑28766) in Gardyn that reveals user data via an unauthenticated endpoint, with no PoC or exploitation evidence shared.

