CVE-2026-32662 Details
Description
Development and test API endpoints are present that mirror production functionality.
A vulnerability exists in the Gardyn Home Kit and Gardyn Studio ecosystems, where development and test API endpoints replicate production functionality. This issue could allow unauthenticated users to access and control edge devices, retrieve cloud-based device and user information, and pivot to other edge devices managed within the Gardyn cloud environment. The vulnerability affects the Gardyn Cloud API in versions prior to 2.12.2026.
Users are advised to update their Gardyn Home Kit and Studio devices to the latest firmware version, master.622 or later. For the Gardyn mobile application, users should update to version 2.11.0 or later. Further information on Gardyn security can be found on the Gardyn security webpage, and customer support is available via email.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-055-03.json | [email protected] | Third Party Advisory |
| https://mygardyn.com/security/ | [email protected] | Vendor Advisory |
| https://www.cisa.gov/news-events/ics-advisories/icsa-26-055-03 | [email protected] | US Government Resource |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-489 | Active Debug Code | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| mygardyn cloud api | < 2.12.2026 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 22, 2026 | Initial Analysis | [email protected] |
| Apr 3, 2026 | New CVE Received | [email protected] |