CVE-2026-50082 Details
Description
The Aqara Cloud Developer Portal (developer.aqara.com) issued a developer token to any email address supplied by the attacker. This is an instance of "CWE-306: Missing Authentication for Critical Function" with an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N (6.5 Medium). When combined with CVE-2026-50083, CVE-2026-50084, and CVE-2026-50085, any otherwise-unauthenticated attacker could execute a full takeover of affected devices.
A vulnerability exists in the Aqara Cloud Developer Portal that allows an attacker to create a developer account using any email address. The portal sends a verification code to the provided email, enabling the attacker to complete the signup process without any approval. This issue, classified as 'CWE-306: Missing Authentication for Critical Function', has an estimated CVSS score of 6.5 (Medium). This vulnerability is the first step in a chain that, when combined with three other CVEs, allows for a complete takeover of affected devices.
Aqara has acknowledged this vulnerability and marked it as fixed. However, independent verification of the fix is pending.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 12, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/xn0tsa/theres-no-place-like-home | CISA-ADP | ExploitThird Party Advisory |
| https://github.com/xn0tsa/theres-no-place-like-home | runZero | ExploitThird Party Advisory |
| https://www.runzero.com/advisories/aqara-dev-portal-auth-token-2026-50082 | runZero | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | runZero |
Affected Products
| Product | Versions |
|---|---|
| aqara cloud developer portal | 2026-04-20 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 10, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | runZero |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 12, 2026 | CVE Modified | CISA-ADP |
| Jun 12, 2026 | New CVE Received | runZero |