Skip to main content

Vendor/product archive

mygardyn / cloud_api CVEs

Beta · best-effort

5 CVEs tagged to mygardyn / cloud_api2 Critical, 1 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2026-32662

Published Apr 3, 2026

Development and test API endpoints are present that mirror production functionality.

CVSS 6.9 · Medium
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-32646

Published Apr 3, 2026

A specific administrative endpoint is accessible without proper authentication, exposing device management functions.

CVSS 8.7 · High
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-28767

Published Apr 3, 2026

A specific administrative endpoint notifications is accessible without proper authentication.

CVSS 6.9 · Medium
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-28766

Published Apr 3, 2026

A specific endpoint exposes all user account information for registered Gardyn users without requiring authentication.

CVSS 9.2 · Critical
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-25197

Published Apr 3, 2026

A specific endpoint allows authenticated users to pivot to other user profiles by modifying the id number in the API call.

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1