Researcher Sammy Azdoufal publicly disclosed a broad set of vulnerabilities in Aqara’s cloud platform, including CVE-2026-50084, a critical authorization flaw in the production API that allowed any valid developer token to access user-scoped endpoints for arbitrary accounts. The issue, rated CVSS 9.6 and classified as CWE-862, affected open-cn.aqara.com/v3.0/open/api and stemmed from missing per-account authorization checks rather than the platform’s MD5-based request-signing scheme. Aqara said the flaw was fixed in April, before public disclosure, but the researcher reported mixed remediation status across the wider set of findings.
The disclosure tied ten CVEs to Aqara cloud, mobile, and developer systems, including hardcoded OAuth credentials in the IAM/SSO gateway (CVE-2026-50083), an unauthenticated MQTT debug interface in Aqara Board (CVE-2026-50085), an unauthenticated AES oracle (CVE-2026-50086), permissive CORS issues (CVE-2026-50087, CVE-2026-50088), an OAuth redirect_uri validation bypass (CVE-2026-50090), and hardcoded cryptographic keys in the Aqara Home Android SDK (CVE-2026-50091). According to the advisory and CVE records, several of these flaws could be chained with CVE-2026-50084 to achieve fully unauthenticated remote takeover of affected devices, while the GitHub disclosure also alleged additional exposures in Aqara back-office infrastructure and disputed the vendor’s claim that the impact was limited to test environments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
On 2026-06-12, CVE-2026-50091 was recorded for hard-coded cryptographic keys in Aqara Home Android 6.0.0 and white-label clients using the same library. The entry said the flaw could severely impact confidentiality and integrity.
A new vulnerability, CVE-2026-50090, was recorded on 2026-06-12 for Aqara's OAuth authorization endpoint at open-cn.aqara.com/oauth/authorize. The issue was described as a redirect_uri validation bypass caused by lax domain matching.
On 2026-06-12, CVE-2026-50088 was recorded for a cross-origin resource sharing weakness affecting developer.aqara.com and related test environments. The entry said the policy was permissive toward untrusted domains.
A new vulnerability entry, CVE-2026-50087, was recorded on 2026-06-12 for a permissive cross-origin resource sharing policy on Aqara's IAM/SSO gateway. The issue affected gw-builder.aqara.com.
On 2026-06-12, CVE-2026-50086 was recorded for the Aqara IAM/SSO gateway at gw-builder.aqara.com. The entry described unauthenticated access to bidirectional AES operations against the platform's signing key.
A new CVE entry, CVE-2026-50085, was added on 2026-06-12 for an authentication flaw in the Aqara Board service at op-test.aqara.com. The service reportedly accepted arbitrary MQTT command payloads and forwarded them without authentication.
On 2026-06-12, CVE-2026-50084 was publicly documented as a critical missing-authorization flaw in the Aqara Cloud Production API. The advisory said any valid developer token could access user-scope endpoints for arbitrary accounts and that the issue could be chained with other Aqara flaws.
A new CVE entry for CVE-2026-50083 was added on 2026-06-12 covering hardcoded OAuth client credentials in the Aqara IAM/SSO Gateway at gw-builder.aqara.com. The entry said the flaw could contribute to a chained unauthenticated remote takeover scenario.
On 2026-06-11, researcher Sammy Azdoufal published a GitHub report disclosing ten CVEs affecting Aqara's cloud platform, including a four-step unauthenticated chain that allegedly enabled remote device takeover. The report also said Aqara had acknowledged 26 of 27 findings, marked them fixed in April 2026, and that several issues remained vulnerable or only partially resolved as of disclosure.
The vendor said the authorization flaw tracked as CVE-2026-50084 was fixed on 2026-04-20. The issue affected the Aqara Cloud Production API and allowed any valid developer token to access arbitrary Aqara accounts.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
10 references tracked. Mallory keeps watching after this page renders.
runzero.com
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.