CVE detail
CVE-2026-28767
A specific administrative endpoint notifications is accessible without proper authentication.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 13.9 · diversity 15.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
3 source links · newest first
No excerpt available.
Mitigationwww.cisa.govApr 3, 2026, 9:17 PM- https://mygardyn.com/security/mygardyn.com
No excerpt available.
Vendor Advisorymygardyn.comApr 3, 2026, 9:17 PM No excerpt available.
Exploitgithub.comApr 3, 2026, 9:17 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-32646CVSS 8.7 · High
A specific administrative endpoint is accessible without proper authentication, exposing device management functions.
- CVE-2026-28766CVSS 9.2 · Critical
A specific endpoint exposes all user account information for registered Gardyn users without requiring authentication.
- CVE-2026-67594CVSS 9.3 · Critical
Spikster through commit e1cdf8c contains a missing authentication vulnerability that allows unauthenticated remote attackers to access all API routes by exploiting the unattached…
- CVE-2026-67208CVSS 9.3 · Critical
Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remote attackers to execute arbitrary OS commands by connecting to the exposed H2 d…
- CVE-2026-67349CVSS 8.7 · High
OpenCost before 1.121.0 fails to authenticate the GET /helmValues endpoint, exposing base64-decoded HELM_VALUES environment variable containing cloud provider credentials. Additio…
- CVE-2026-12722CVSS 8.2 · High
Missing authentication for critical function vulnerability in FTC Software IT Services FTC E-Commerce Management Panel allows Authentication Bypass. This issue affects FTC E-Comm…