CVE-2026-33359

In Meari IoT Cloud alert image storage on Alibaba OSS (latest observed; storage service version not disclosed), motion snapshots are retrievable without authentication, signed URLs, or expiry enforcement. URLs function as direct object references and remain valid beyond expected operational windows.
Configurations

No configuration.

History

No history.

Information

Published : 2026-05-11 17:16

Updated : 2026-06-17 10:37


NVD link : CVE-2026-33359

Mitre link : CVE-2026-33359

CVE.ORG link : CVE-2026-33359


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization