CVE-2026-28767 Details
Description
A specific administrative endpoint notifications is accessible without proper authentication.
A vulnerability exists in the Gardyn Home Kit and Gardyn Studio ecosystems, allowing unauthenticated users to access a specific administrative endpoint for notifications. This endpoint is part of the Gardyn Cloud API and is accessible without proper authentication, potentially leading to unauthorized access and control over connected edge devices. The vulnerability affects several components of the Gardyn ecosystem, including the Gardyn Home Kit firmware, Gardyn Studio firmware, and the Gardyn mobile application versions prior to 2.11.0.
Users are advised to update their Gardyn mobile application to version 2.11.0 or later. For Gardyn Home Kit and Studio devices, ensure that the firmware is updated to version master.622 or later. Connected devices will automatically receive the update when online. For further assistance, contact Gardyn support.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 7, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-055-03.json | [email protected] | Third Party Advisory |
| https://mygardyn.com/security/ | [email protected] | Vendor Advisory |
| https://www.cisa.gov/news-events/ics-advisories/icsa-26-055-03 | [email protected] | Third Party AdvisoryUS Government Resource |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| mygardyn cloud api | < 2.12.2026 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 22, 2026 | Initial Analysis | [email protected] |
| Apr 3, 2026 | New CVE Received | [email protected] |