CVE-2026-55726 Details
Description
The Azure Blob Storage container used for Gardyn device logs is publicly listable without authentication. A malicious user would be able to access any device log file available in the blob storage container.
A vulnerability exists in the Azure Blob Storage container used for Gardyn device logs, which is publicly accessible without authentication. This exposure allows unauthorized users to access any available device log file. The issue affects all versions of the Gardyn IoT Hub Home and Studio firmware, as well as the Cloud API versions prior to 2.12.2026.
Gardyn has updated the IoT Hub infrastructure to address this vulnerability. Users should ensure their devices are connected to the Internet to receive the update automatically. Unconnected devices will update once a working Internet connection is established. For the Gardyn mobile application, users should update to the latest version. Current app and firmware versions can be checked within the Gardyn App. Further information on Gardyn security is available on the Gardyn security webpage, and customer support can be contacted via email.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-497 | Exposure of Sensitive System Information to an Unauthorized Control Sphere | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 6, 2026 | CVE Modified | CISA-ADP |
| Jul 3, 2026 | New CVE Received | [email protected] |