The Aqara IAM/SSO gateway (gw-builder.aqara.com) exposes bidirectional AES round-trips against the platform's signing key without authentication. This enables cryptographic operations using the platform's signing key to be performed by unauthorized parties.
An unauthenticated attacker over the network can perform AES cryptographic operations using the platform's signing key, enabling them to forge authentication tokens and potentially gain unauthorized access to the platform.
There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.
Apply the available security patch from the GitHub advisory (GHSA-3897-2crh-vgmr) immediately. Additionally, implement authentication controls on the IAM/SSO gateway endpoints to restrict access to cryptographic functions. Consider reviewing all access logs to the exposed endpoints for signs of exploitation.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
NVD published the first details for CVE-2026-50086
Feedly found the first article mentioning CVE-2026-50086 . See article
GitHub Advisories released a security advisory .
[GHSA-3897-2crh-vgmr] The Aqara IAM/SSO gateway (gw-builder.aqara.com) exposes bidirectional AES round
CVE-2026-50086 | Aqara IAM SSO Gateway up to 3.1/7.5 risky encryption
Collect, analyze, and vulnerability reports faster using AI
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
