Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-28767 — CVE-2026-28767: Missing Authentication on Admin Notifications Endpoint — Gardyn Home Kit (ICSA-26-055-03) | Kitploit
Tools/GitHubGitHub/michaeladamgroberman/cve-2026-28767
IoT SecurityVulnerability AnalysisWeb SecurityCloud SecurityMisconfigurationAPI Security
GitHubmichaeladamgroberman/cve-2026-28767

CVE-2026-28767

CVE-2026-28767: Missing Authentication on Admin Notifications Endpoint — Gardyn Home Kit (ICSA-26-055-03)

View Repository
2 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Website

CVE-2026-28767: Missing Authentication on Administrative Notifications Endpoint

Advisory

FieldValue
CVECVE-2026-28767
ICSAICSA-26-055-03 (Update A)
CVSS 3.15.3 (Medium)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CWECWE-306 (Missing Authentication for Critical Function)
ResearcherMichael Groberman — Gr0m
Published2026-04-02 (Update A)

Product

FieldValue
VendorGardyn
ProductGardyn Home Kit 1.0, 2.0, 3.0, 4.0; Gardyn Studio 1.0, 2.0
ComponentCloud API
Affected VersionsCloud API < 2.12.2026

Summary

The /api/admin/notifications administrative endpoint is accessible without authentication, exposing internal notification system data and administrative communications to unauthenticated users.

Vulnerability Details

Unauthenticated Access

The administrative notifications endpoint is publicly accessible without any authentication or authorization controls:

root@kitploit:~
GET [REDACTED — Cloud API host]/api/admin/notifications
Authentication: NONE

Exposed Data

The unauthenticated endpoint provides access to:

  • Internal notification system data and message templates
  • Administrative communications and system alerts
  • Push notification configurations and delivery status
  • User notification preferences and targeting data

Systemic Pattern

This endpoint is part of a broader pattern of missing authentication on the Gardyn /api/admin/* path. Both /api/admin/devices (CVE-2026-32646) and /api/admin/notifications lack authentication, suggesting the entire administrative API namespace may have been deployed without access controls.

Impact

  • Information disclosure of internal administrative communications
  • Visibility into operational processes and system events
  • Notification template and targeting data exposure
  • Reconnaissance value for identifying system behavior, user engagement patterns, and administrative workflows
  • Potential for notification injection or modification if write operations are exposed

Standard Services Available for This Class of Endpoint

ServicePurpose
Azure App Service Authentication (Easy Auth)Built-in authentication middleware — a single toggle protects all endpoints
Azure App Service Access RestrictionsIP-based or VNet-based access rules to restrict who can reach specific endpoints

Remediation

Gardyn recommends upgrading to Cloud API version 2.12.2026 or later. See https://mygardyn.com/security/ for additional information.

Recommended fix for the vendor:

  1. Require administrative authentication on all /api/admin/* endpoints
  2. Implement role-based access control for administrative operations
  3. Audit all endpoints under the /api/admin/ path for missing authentication
  4. Place administrative endpoints behind a separate access-controlled path
  5. Audit access logs for unauthorized access to administrative endpoints

Timeline

DateEvent
2025-10-14Initial disclosure to vendor
2025-12-11Disclosure to CERT/CC
2026-02-24ICSA-26-055-03 published (initial)
2026-04-02ICSA-26-055-03 Update A -- CVE-2026-28767 added

References

  • CVE-2026-28767 -- CVE Record
  • ICSA-26-055-03
  • CWE-306: Missing Authentication for Critical Function

Credit

Reported by Michael Groberman — Gr0m to CISA.

Download Tool