Skip to content
CVE-2026-50086 - Exploits & Severity

CVE-2026-50086 - Exploits & Severity

Feedly June 12, 2026

The Aqara IAM/SSO gateway (gw-builder.aqara.com) exposes bidirectional AES round-trips against the platform's signing key without authentication. This enables cryptographic operations using the platform's signing key to be performed by unauthorized parties.

An unauthenticated attacker over the network can perform AES cryptographic operations using the platform's signing key, enabling them to forge authentication tokens and potentially gain unauthorized access to the platform.

There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.

Apply the available security patch from the GitHub advisory (GHSA-3897-2crh-vgmr) immediately. Additionally, implement authentication controls on the IAM/SSO gateway endpoints to restrict access to cryptographic functions. Consider reviewing all access logs to the exposed endpoints for signs of exploitation.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

NVD published the first details for CVE-2026-50086

Feedly found the first article mentioning CVE-2026-50086 . See article

GitHub Advisories released a security advisory .

[GHSA-3897-2crh-vgmr] The Aqara IAM/SSO gateway (gw-builder.aqara.com) exposes bidirectional AES round

CVE-2026-50086 | Aqara IAM SSO Gateway up to 3.1/7.5 risky encryption

Collect, analyze, and vulnerability reports faster using AI

Extracted Entities

Attack Types (1)

Companies (1)

Platforms (1)