CVE-2026-50086Authentication bypass in Aqara IAM/SSO gateway
The Aqara IAM/SSO gateway (gw-builder.aqara.com) exposes bidirectional AES round-trups against the platform's signing key without authentication. This is an instance of "CWE-306: Missing Authentication for Critical Function" and "CWE-327: Use of a Broken or Risky Cryptographic Algorithm," and has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N (7.5 High).
View on NVDAnalysis
El gateway de IAM/SSO de Aqara permite realizar operaciones de cifrado AES con la llave de firma de la plataforma sin requerir ninguna autenticación. Esta vulnerabilidad crítica permite que atacantes comprometan la integridad del sistema de identidad y acceso de forma remota. Es fundamental para quienes integran servicios de Aqara revisar sus implementaciones de autenticación de inmediato.
Relevant roles
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HCWE-327EPSS
Affects
aqara:iam\/sso_gatewayTechnical description
The Aqara IAM/SSO gateway (gw-builder.aqara.com) exposes bidirectional AES round-trups against the platform's signing key without authentication. This is an instance of "CWE-306: Missing Authentication for Critical Function" and "CWE-327: Use of a Broken or Risky Cryptographic Algorithm," and has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N (7.5 High).