CVE-2026-33359 Details
Description
In Meari IoT Cloud alert image storage on Alibaba OSS (latest observed; storage service version not disclosed), motion snapshots are retrievable without authentication, signed URLs, or expiry enforcement. URLs function as direct object references and remain valid beyond expected operational windows.
A vulnerability exists in the Meari IoT Cloud service, specifically in the storage of alert images on Alibaba OSS. Motion snapshots can be accessed without authentication, signed URLs, or expiration enforcement. The URLs, which act as direct object references, remain valid indefinitely, leading to unauthorized access to private indoor and baby-monitor camera images.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 11, 2026CISA-ADP
Assessed May 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/xn0tsa/nobody-puts-baby-in-a-corner | runZero | BundleTechnical Analysis |
| https://www.runzero.com/advisories/meari-unauthenticated-alert-image-access-in-cloud-object-storage-cve-2026-33359/ | runZero | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | runZero |
Affected Products
| Product | Versions |
|---|---|
| Meari IoT Cloud | All versions |
CPE
Remediation
| |
| Alibaba OSS | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | runZero |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 11, 2026 | New CVE Received | runZero |
Volerion