CVE-2026-50086

The Aqara IAM/SSO gateway (gw-builder.aqara.com) exposes bidirectional AES round-trups against the platform's signing key without authentication. This is an instance of "CWE-306: Missing Authentication for Critical Function" and "CWE-327: Use of a Broken or Risky Cryptographic Algorithm," and has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N (7.5 High).
Configurations

Configuration 1 (hide)

cpe:2.3:a:aqara:iam\/sso_gateway:2026-04-20:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-06-12 16:16

Updated : 2026-07-09 16:04


NVD link : CVE-2026-50086

Mitre link : CVE-2026-50086

CVE.ORG link : CVE-2026-50086


JSON object : View

Products Affected

aqara

  • iam\/sso_gateway
CWE
CWE-327

Use of a Broken or Risky Cryptographic Algorithm