๐Ÿ” CVE Alert

CVE-2026-50082

MEDIUM 6.5

Aqara Developer Portal insecure authentication token

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

The Aqara Cloud Developer Portal (developer.aqara.com) issued a developer token to any email address supplied by the attacker. This is an instance of "CWE-306: Missing Authentication for Critical Function" with an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N (6.5 Medium). When combined with CVE-2026-50083, CVE-2026-50084, and CVE-2026-50085, any otherwise-unauthenticated attacker could execute a full takeover of affected devices.

CWE CWE-306
Vendor aqara
Product cloud developer portal
Published Jun 12, 2026
Last Updated Jun 12, 2026
Stay Ahead of the Next One

Get instant alerts for aqara cloud developer portal

Be the first to know when new medium vulnerabilities affecting aqara cloud developer portal are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

Aqara / Cloud Developer Portal
2026-04-20 < 0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/xn0tsa/theres-no-place-like-home runzero.com: https://www.runzero.com/advisories/aqara-dev-portal-auth-token-2026-50082

Credits

Sammy Azdoufal Tod Beardsley of runZero, Inc.