CVE-2026-50086 Details
Description
The Aqara IAM/SSO gateway (gw-builder.aqara.com) exposes bidirectional AES round-trups against the platform's signing key without authentication. This is an instance of "CWE-306: Missing Authentication for Critical Function" and "CWE-327: Use of a Broken or Risky Cryptographic Algorithm," and has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N (7.5 High).
A vulnerability exists in the Aqara IAM/SSO gateway, specifically on the domain gw-builder.aqara.com. This vulnerability allows for bidirectional AES encryption and decryption operations using the platform's signing key, all without any authentication. The issue arises from a combination of missing authentication for critical functions and the use of a risky cryptographic algorithm, AES in ECB mode, which is known to be insecure. The vulnerability has a CVSS score of 7.5, classified as high.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 12, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/xn0tsa/theres-no-place-like-home | CISA-ADP | ExploitThird Party Advisory |
| https://github.com/xn0tsa/theres-no-place-like-home | runZero | ExploitThird Party Advisory |
| https://www.runzero.com/advisories/aqara-unauth-aes-oracle-cve-2026-50086 | runZero | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-327 | Use of a Broken or Risky Cryptographic Algorithm | runZero |
Affected Products
| Product | Versions |
|---|---|
| aqara iam/sso gateway | 2026-04-20 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 9, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | runZero |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 12, 2026 | CVE Modified | CISA-ADP |
| Jun 12, 2026 | New CVE Received | runZero |