
CVE-2026-50082 CVE-2026-50083 CVE-2026-50084 CVE-2026-50085 CVE-2026-50086 CVE-2026-50087 CVE-2026-50088 CVE-2026-50089 CVE-2026-50090 CVE-2026-50091
Post summary
The text only lists CVE identifiers and provides no further details or context.
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
The Aqara IAM/SSO Gateway (gw-builder.aqara.com) provides an open redirect, which is an instance of "CWE-601: URL Redirection to Untrusted Site," with an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N (6.1 Medium), which can be used to set up a phishing attack.
Priority
LOW
Exploitation
NONE
PoC
YES
Patch
NONE
Momentum
NONE
If you run products in this scope, you should treat this CVE as relevant to your environment.
1 version affected across 1 product

CVE-2026-50082 CVE-2026-50083 CVE-2026-50084 CVE-2026-50085 CVE-2026-50086 CVE-2026-50087 CVE-2026-50088 CVE-2026-50089 CVE-2026-50090 CVE-2026-50091
Post summary
The text only lists CVE identifiers and provides no further details or context.
1 of 1 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | aqara | iam\/sso_gateway | 2026-04-20 | - | - |