Skip to main content

Vendor/product archive

aqara / cloud_oauth_authorization_endpoint CVEs

Beta · best-effort

1 CVEs tagged to aqara / cloud_oauth_authorization_endpoint1 Critical, 0 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2026-50090

Published Jun 12, 2026

The Aqara Cloud OAuth Authorization Endpoint (open-cn.aqara.com/oauth/authorize) is vulnerable to a redirect bypass due to lax controls on domain matching, which is an instance of…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
22.0
Public PoC observed
Vendor/product tagsBeta · best-effort
Showing 1-1 of 1 CVEsPage 1 of 1