
CVE-2026-28767: Missing Authentication on Admin Notifications Endpoint — Gardyn Home Kit (ICSA-26-055-03)
| Field | Value |
|---|---|
| CVE | CVE-2026-28767 |
| ICSA | ICSA-26-055-03 (Update A) |
| CVSS 3.1 | 5.3 (Medium) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
| CWE | CWE-306 (Missing Authentication for Critical Function) |
| Researcher | Michael Groberman — Gr0m |
| Published | 2026-04-02 (Update A) |
| Field | Value |
|---|---|
| Vendor | Gardyn |
| Product | Gardyn Home Kit 1.0, 2.0, 3.0, 4.0; Gardyn Studio 1.0, 2.0 |
| Component | Cloud API |
| Affected Versions | Cloud API < 2.12.2026 |
The /api/admin/notifications administrative endpoint is accessible without authentication, exposing internal notification system data and administrative communications to unauthenticated users.
The administrative notifications endpoint is publicly accessible without any authentication or authorization controls:
GET [REDACTED — Cloud API host]/api/admin/notifications
Authentication: NONE
The unauthenticated endpoint provides access to:
This endpoint is part of a broader pattern of missing authentication on the Gardyn /api/admin/* path. Both /api/admin/devices (CVE-2026-32646) and /api/admin/notifications lack authentication, suggesting the entire administrative API namespace may have been deployed without access controls.
| Service | Purpose |
|---|---|
| Azure App Service Authentication (Easy Auth) | Built-in authentication middleware — a single toggle protects all endpoints |
| Azure App Service Access Restrictions | IP-based or VNet-based access rules to restrict who can reach specific endpoints |
Gardyn recommends upgrading to Cloud API version 2.12.2026 or later. See https://mygardyn.com/security/ for additional information.
Recommended fix for the vendor:
/api/admin/* endpoints/api/admin/ path for missing authentication| Date | Event |
|---|---|
| 2025-10-14 | Initial disclosure to vendor |
| 2025-12-11 | Disclosure to CERT/CC |
| 2026-02-24 | ICSA-26-055-03 published (initial) |
| 2026-04-02 | ICSA-26-055-03 Update A -- CVE-2026-28767 added |
Reported by Michael Groberman — Gr0m to CISA.