Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-28766 — CVE-2026-28766: Missing Authentication on User Account Endpoint — Gardyn Home Kit (ICSA-26-055-03) | Kitploit
Tools/GitHubGitHub/michaeladamgroberman/cve-2026-28766
IoT SecurityVulnerability AnalysisInformation GatheringCloud SecurityAuthenticationAPI Security
GitHubmichaeladamgroberman/cve-2026-28766

CVE-2026-28766

CVE-2026-28766: Missing Authentication on User Account Endpoint — Gardyn Home Kit (ICSA-26-055-03)

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View RepositoryWebsite
2 months agoNot yet reviewed

CVE-2026-28766

Missing Authentication: User Account Endpoint

FieldValue
CVECVE-2026-28766
SeverityCritical (9.3)
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
Weakness (CWE)CWE-306: Missing Authentication for Critical Function
Affected componentsCloud API <2.12.2026
VendorGardyn Inc.
Affected productsGardyn Home Kit Models 1.0, 2.0, 3.0, 4.0; Gardyn Studio Models 1.0, 2.0
SectorFood and Agriculture (CISA classification)
Status per CISA Update ARemediated

What is documented

Per the CISA advisory, an unauthenticated cloud API endpoint (/api/users) exposed records described in the advisory as "all user account information" for approximately 134,215 customers.

A separately-cataloged single-record companion endpoint (/api/user/{id}, published as CVE-2026-25197) returned per-user records — including physical addresses — by sequential integer ID with no authentication, making the same user space enumerable one record at a time.

Primary sources

  • CISA ICSA-26-055-03 (Update A)
  • NVD: CVE-2026-28766
  • MITRE CVE Record: CVE-2026-28766

Mitigation per CISA Update A

Per CISA Update A (April 2, 2026), this CVE is remediated. The fix versions stated by CISA are: Gardyn mobile application 2.11.0 or later; Gardyn cloud API 2.12.2026 or later; Home Kit firmware master.622 or later.

Credit

Reported by Michael Groberman — Gr0m to CISA via CERT/CC VINCE Case VU#653116.

Download Tool