CVE-2026-28806 Details
Description
Improper Authorization vulnerability in nerves-hub nerves_hub_web allows cross-organization device control via device bulk actions and device update API. Missing authorization checks in the device bulk actions and device update API endpoints allow authenticated users to target devices belonging to other organizations and perform actions outside of their privilege level. An attacker can select devices outside of their organization by manipulating device identifiers and perform management actions on them, such as moving them to products they control. This may allow attackers to interfere with firmware updates, access device functionality exposed by the platform, or disrupt device connectivity. In environments where additional features such as remote console access are enabled, this could lead to full compromise of affected devices. This issue affects nerves_hub_web: from 1.0.0 before 2.4.0.
A critical improper authorization vulnerability has been identified in the Nerves Hub Web device bulk actions and update API endpoints. This vulnerability allows authenticated users to manipulate device identifiers and target devices belonging to other organizations, performing actions beyond their authorized privileges. Exploitation could involve moving devices to different products, interfering with firmware updates, or disrupting device connectivity. In environments with remote console access, this could lead to a complete compromise of the affected devices. The vulnerability affects Nerves Hub Web versions 1.0.0 prior to 2.4.0.
Users can update to Nerves Hub Web version 2.4.0 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cna.erlef.org/cves/CVE-2026-28806.html | EEF | PatchThird Party Advisory |
| https://github.com/nerves-hub/nerves_hub_web/commit/1f69c9d595684a4650c3ac702f3dc7c5bcd7526c | EEF | Patch |
| https://github.com/nerves-hub/nerves_hub_web/security/advisories/GHSA-f8fr-mccc-xvcx | EEF | PatchVendor Advisory |
| https://osv.dev/vulnerability/EEF-CVE-2026-28806 | EEF | PatchThird Party Advisory |
Weakness Enumeration
Affected Products
| Product | Versions |
|---|---|
| nerves-hub nerveshub | >= 1.0.0, < 2.4.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | EEF |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 27, 2026 | Initial Analysis | [email protected] |
| Apr 6, 2026 | CVE Modified | EEF |
| Mar 10, 2026 | New CVE Received | EEF |