CVE-2026-33359Disclosure

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In Meari IoT Cloud alert image storage on Alibaba OSS (latest observed; storage service version not disclosed), motion snapshots are retrievable without authentication, signed URLs, or expiry enforcement. URLs function as direct object references and remain valid beyond expected operational windows.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-11: 2Technical Details · 2026-05-11: 205-11
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Sammy Azdoufal@n0tsa
    Disclosure

    5/ CVE-2026-33359 (CVSS 7.5) : Motion alert images, forever. When your camera detects motion, it uploads a JPEG to Alibaba OSS. The URL is broadcast in the MQTT stream. No signed URLs. No expiry. No auth. The link works for anyone, forever.

    Post summary

    CVE-2026-33359 reveals that motion‑triggered JPEGs uploaded to Alibaba OSS are publicly accessible via URLs that never expire, lacking authentication or signed URLs. The post provides an overview of the vulnerability but no exploitation code, patch, or evidence of active attacks.

    110501.2K
    11.7K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33359 In Meari IoT Cloud alert image storage on Alibaba OSS (latest observed; storage service version not disclosed), motion snapshots are retrievable without authenticatio… https://www.cve.org/CVERecord?id=CVE-2026-33359

    Post summary

    CVE-2026-33359 reveals that unauthenticated users can access motion snapshot images from Meari IoT Cloud’s Alibaba OSS storage, exposing sensitive media to the public.

    00000152
    57.5K followersView on X

Explore more