Gardyn disclosed two high-severity vulnerabilities affecting its cloud API, mobile application, and device firmware that could allow unauthorized access to sensitive data without prior authentication. CVE-2026-28766 is a CWE-306 missing-authentication flaw in a user-facing cloud endpoint that returns all registered user account information even when no authentication is provided, creating a direct path to broad data exposure over the network with no user interaction required.
A second issue, CVE-2025-10681, is a CWE-798 hard-coded credentials flaw in the Gardyn mobile app and device firmware. The embedded storage credentials reportedly grant overly broad permissions and do not expire within a reasonable time, potentially enabling unauthorized access to production storage containers and increasing the risk of confidentiality loss. Both records were published through CISA-linked advisories and vendor security references, indicating coordinated disclosure across federal and vendor channels.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
ICS-CERT received the vulnerability record for CVE-2026-25197 on 2026-04-03. The Gardyn cloud API flaw allows users to access or pivot to other user profiles by modifying an ID value in an API request, a CWE-639 insecure direct object reference issue.
ICS-CERT newly received the vulnerability record for CVE-2026-28766 on 2026-04-03. The flaw affects a Gardyn user-facing cloud API endpoint that returns all registered user account information without requiring authentication.
ICS-CERT newly received the vulnerability record for CVE-2025-10681 on 2026-04-03. The issue describes hard-coded credentials in the Gardyn mobile application and device firmware that could enable unauthorized access to production storage containers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.