Skip to main content
Mallory
CriticalPublic exploit

Unauthenticated AES Oracle in Aqara IAM/SSO Gateway

IdentifiersCVE-2026-50086CWE-306

CVE-2026-50086 affects the Aqara IAM/SSO gateway at gw-builder.aqara.com. Two exposed endpoints provide bidirectional AES operations—encrypt and decrypt round-trips—using the platform's signing key, and these cryptographic functions are accessible without authentication. Supporting reporting indicates the oracle uses AES in ECB mode, allowing an unauthenticated remote party to submit chosen plaintext or ciphertext and receive the corresponding transformed output under the platform key. The core flaw is exposure of a critical cryptographic function without access control, with an additional cryptographic weakness stemming from the use of a risky mode of operation.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

A remote unauthenticated attacker can use the exposed AES oracle to perform arbitrary encryption and decryption operations under the platform's signing key. This can enable recovery of sensitive information derived from that key, misuse of the signing-key context for unauthorized cryptographic operations, and compromise of confidentiality for data protected by the affected mechanism. Given that the oracle is bidirectional and internet-accessible, the issue may also facilitate forgery or abuse of downstream trust decisions that rely on the same key material or encrypted artifacts, depending on how the signing key is used elsewhere in the Aqara platform.

Mitigation

If you can’t patch tonight, do this now.

Until a full fix is deployed, disable or firewall public access to the vulnerable gw-builder.aqara.com endpoints, restrict them to trusted administrative networks if operationally necessary, and monitor for requests indicative of oracle abuse. Apply WAF or API gateway rules to block unauthenticated access to the affected paths. As a precaution, rotate signing keys and invalidate tokens, signatures, or artifacts that may depend on the exposed key if there is any possibility the oracle was abused. Conduct log review for repeated chosen-input requests to the relevant endpoints.

Remediation

Patch, then assume compromise.

Restrict access to the affected AES encrypt/decrypt endpoints by requiring strong authentication and authorization for any cryptographic operation involving platform key material. Remove any externally exposed oracle behavior that permits arbitrary client-supplied plaintext or ciphertext to be processed under sensitive keys. Rotate the affected platform signing key and any derived or related credentials after remediation, because prior unauthenticated access may have exposed key-dependent operations. Review all uses of the same key across the IAM/SSO and related services, and replace ECB-based constructions with a modern, purpose-appropriate cryptographic design that does not expose raw encryption/decryption primitives to untrusted callers.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
AqaraIam Sso Gatewayapplication

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity6

Community discussion across Reddit, Mastodon, and other social sources.