Gardyn Security Incident

Gardyn Security Incident

Independent documentation of CISA advisories ICSA-26-055-03 (Update B) and ICSA-26-183-03 (Gardyn IoT Hub) and the thirteen related CVEs affecting the Gardyn IoT platform.

13CVEs across two advisories
134,215user records (per CVE-2026-28766)
CVSS 10.0CVE-2026-13768 (IoT Hub)
CISAICSA-26-055-03 & ICSA-26-183-03

What is documented in primary sources

Per CISA advisory ICSA-26-055-03 Update A (April 2, 2026), an unauthenticated cloud API endpoint exposed records described in the advisory as “all user account information” for approximately 134,215 customers (CVE-2026-28766). Per the maintainer’s coordinated-disclosure repository, the records returned by /api/users included names, email addresses, phone numbers, and a partial payment-card field (last_four), not full card number or CVV. A separately-cataloged single-record companion endpoint (/api/user/{id}, CVE-2026-25197) returned per-user records — including physical addresses — by sequential integer ID with no authentication. Per Gardyn’s customer-facing security update post, the vulnerabilities did not expose payment card information.

Side-by-side: vendor statements vs. CISA findings →

Where to go from here

Gardyn customerWhat was exposed and what to do JournalistPress kit, on-record contact, source materials ResearcherPer-CVE technical detail, GitHub repositories

About this site

This site documents the Gardyn IoT security incident publicly disclosed by CISA on February 24, 2026, expanded to ten CVEs via Update A on April 2, 2026, and revised again by Update B on July 2, 2026. On the same day, CISA published the companion advisory ICSA-26-183-03 (Gardyn IoT Hub) with three further CVEs, bringing the total to thirteen across two advisories. CISA credits Michael Groberman as the reporting researcher in the advisory. Per the maintainer’s coordinated-disclosure repository, initial private disclosure to Gardyn was on October 14, 2025, made in his self-identified capacity as a Gardyn customer with technical knowledge whose own account record was among the records exposed; the “researcher” label was applied by CISA on February 24, 2026 with the publication of the advisory.

Every claim on this site links to a primary public record: the CISA advisory, the National Vulnerability Database, MITRE CVE records, the maintainer’s coordinated-disclosure repository, or Gardyn’s own customer-facing posts. The methodology page describes the sourcing standard.

ICSA-26-055-03 — the ten CVEs (by severity)

CVESeverityTitle (per researcher repository)
CVE-2026-28766Critical (9.3)Missing Authentication: User Account Endpoint
CVE-2025-1242Critical (9.1)Use of Hard-coded Credentials
CVE-2025-29631Critical (9.1)OS Command Injection
CVE-2026-25197Critical (9.1)Authorization Bypass via User-Controlled Key (IDOR)
CVE-2025-10681High (8.6)Hardcoded Azure Blob Storage Account Key
CVE-2025-29628High (8.3)Cleartext Transmission of Sensitive Information
CVE-2025-29629High (8.3)Use of Default Credentials
CVE-2026-32646High (7.5)Missing Authentication: Admin Device Management
CVE-2026-28767Medium (5.3)Missing Authentication: Admin Notifications
CVE-2026-32662Medium (5.3)Active Debug Code in Production

ICSA-26-183-03 (Gardyn IoT Hub) — the three companion CVEs

Per CISA advisory ICSA-26-183-03, published July 2, 2026 with an overall CVSS v3 base score of 10.0.

CVESeverityTitle (per researcher repository)
CVE-2026-13768Critical (10.0)Privileged IoT Hub credential (fleet enumeration, device RCE, home-network pivot)
CVE-2026-54477Medium (5.4)Admin Panel Missing Security Headers (clickjacking / XSS)
CVE-2026-55726Medium (5.3)Publicly Listable Azure Blob Storage Container (device logs)

Quick links