« Volver al listado

Mygardyn

Mygardyn Cloud API: vulnerabilidades y CVE

Mygardyn Cloud API tiene 6 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE6
Últimos 12 meses6
Críticas3
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-68067Crítica (9.3)0.51%—11 ago 2026
The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live active session token for the account matching the supplied email address. An attacker could use an email…
CVE-2026-32662Media (6.9)0.44%—3 abr 2026
Development and test API endpoints are present that mirror production functionality.
CVE-2026-32646Alta (8.7)0.68%—3 abr 2026
A specific administrative endpoint is accessible without proper authentication, exposing device management functions.
CVE-2026-28767Media (6.9)0.53%—3 abr 2026
A specific administrative endpoint notifications is accessible without proper authentication.
CVE-2026-28766Crítica (9.2)0.60%—3 abr 2026
A specific endpoint exposes all user account information for registered Gardyn users without requiring authentication.
CVE-2026-25197Crítica (9.3)0.29%—3 abr 2026
A specific endpoint allows authenticated users to pivot to other user profiles by modifying the id number in the API call.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1078.001 Default Accounts1
  2. T1190 Exploit Public-Facing Application1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.