CVE-2026-32662
Published Apr 3, 2026Development and test API endpoints are present that mirror production functionality.
- evidence mentions
- 3
- Buzz score
- 28.9
Vendor/product archive
5 CVEs tagged to mygardyn / cloud_api — 2 Critical, 1 High, 2 Medium, 0 Low, 0 Unrated.
Development and test API endpoints are present that mirror production functionality.
A specific administrative endpoint is accessible without proper authentication, exposing device management functions.
A specific administrative endpoint notifications is accessible without proper authentication.
A specific endpoint exposes all user account information for registered Gardyn users without requiring authentication.
A specific endpoint allows authenticated users to pivot to other user profiles by modifying the id number in the API call.