Skip to content
Critical Vulnerability in Aqara IAM/SSO Gateway Exposes Signing Key

Critical Vulnerability in Aqara IAM/SSO Gateway Exposes Signing Key

First seen 13 Jun 2026, 04:25 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 14, 2026 at 04:20 UTC
  • CVE-2026-50086 allows unauthorized cryptographic operations on Aqara IAM/SSO gateway.
  • Attackers can forge authentication tokens without authentication, posing a significant risk.
  • Immediate patching and implementation of authentication controls are recommended.

The Aqara IAM/SSO gateway (gw-builder.aqara.com) has a critical vulnerability (CVE-2026-50086) that allows unauthorized access to cryptographic operations involving the platform's signing key. This flaw enables attackers to forge authentication tokens without authentication, potentially granting them unauthorized access to the platform. The vulnerability is classified as a 'Missing Authentication for Critical Function' and 'Use of a Broken or Risky Cryptographic Algorithm.' The CVSS score is estimated at 7.5, indicating a high severity. There is currently no evidence of active exploitation or a public proof-of-concept. Security patches have been released, and organizations are advised to implement authentication controls and review access logs. The vulnerability was first published on June 12, 2026.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 89d ago How this analysis works

Timeline

2026-06-12
CVE-2026-50086 published
The vulnerability in the Aqara IAM/SSO gateway was disclosed, exposing critical cryptographic flaws.
Feedly
2026-06-13
Security advisory issued
Organizations are urged to apply the security patch and implement authentication controls to mitigate risks.
cve.akaoma.com

More articles in this cluster (5)

Following this threat?

Track Aqara and CVE-2026-50086 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed