- CISA says two flaws in Meari's IoT cloud service let a logged-in user change or read devices they do not own. Meari plans no fix.
- The vendor's silence leaves the exposure with the organizations that rely on the service. In our view, security reviews rarely test whether a vendor will answer reports.
- Check whether suppliers use the service, contact Meari, rotate credentials where possible, plan a replacement, and require vendors to commit to answering security reports.
A login is not the same as permission
Think of a hotel key card that gets you into the building and then opens every room on the corridor. The card proves you are a guest. It does not check which room is yours.
That is the pattern in a CISA advisory on the Meari IoT Cloud Platform OpenAPI Service. The service checks who a user is. According to CISA, it does not check which devices that user may touch. Both flaws carry the same classification, CWE-862, Missing Authorization.
What CISA reports
CISA published the advisory on October 1, 2026. It lists two CVEs: CVE-2026-101104 and CVE-2026-96613. It says all versions of the service are affected. Gabriel Adams reported the flaws to CISA.
CISA says it tried to coordinate with Meari and got no reply. It lists "No fix planned" for both flaws. It advises users to contact Meari for support.
CISA also says it has received no reports of public exploitation aimed at these flaws. That was true at the time of the advisory.
How the two flaws work
The first flaw lets an authenticated user change the configuration of devices they do not own. CISA says this can alter device settings or trigger unintended behavior. No ownership or permission check happens beforehand.
The second flaw is about data. An authenticated user can request the "complete device shadow" of any device by supplying its device ID. A device shadow is the cloud's stored record of a device and its state.
Per CISA, one such request can return the device's credentials, its owner's details, its network data and the telemetry it reports. Telemetry means the readings a device sends back. Nothing in the lookup confirms that the person asking has any link to the device.
Both flaws need a valid login. The advisory does not say how easily an attacker could get one. It also does not say how device IDs might be found.
When the vendor goes quiet, the customer inherits the risk
A normal flaw has a normal ending: the vendor patches and the customer applies the update. Here CISA reports no response from the vendor and no planned fix. The exposure does not end. It moves to the organizations that depend on the service.
This is the point for executives. In our view, security reviews usually test whether a product has flaws, but rarely test whether the vendor will answer when someone reports one. This advisory shows why the second question matters.
CISA lists the affected sectors as Commercial Facilities and Information Technology. Some organizations may not know whether a supplier's equipment relies on this service. That is a gap worth closing.
Questions to put to your team
First, do any of our products, building systems or suppliers use the Meari IoT Cloud Platform OpenAPI Service? Ask facilities and IT, and ask suppliers directly.
Second, if the answer is yes, contact Meari through the support page CISA names, and keep a record of the reply. Silence is itself information for your risk file.
Third, be clear about what CISA's guidance can do here. It is general hardening advice for control systems: keep devices off the internet, place them behind firewalls, separate them from business networks, and use VPNs for remote access. The flaws sit in the cloud service's authorization checks. In our view, firewalls, segmentation and VPNs on your side do not close that gap. Treat the guidance as basic hygiene, not a fix for these flaws.
Fourth, use the levers you do hold. Where the product allows it, rotate device credentials, since the second flaw can expose them. Decide in advance what service you would swap in if the vendor never fixes these flaws.
Fifth, change what you ask vendors to sign. Require a named security contact and a commitment to answer coordinated disclosure. This is our recommendation, not CISA's.
A login proves who someone is. It says nothing about what they may touch, and a vendor that stays silent leaves that check to you.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: CISA.





