Gardyn Security Incident

CISA Advisory ICSA-26-055-03

All ten CVEs in CISA advisory ICSA-26-055-03, as updated April 2, 2026 (Update A). Each entry links to the canonical NVD record, MITRE CVE record, and per-CVE researcher repository where available.

The advisory

AdvisoryCISA ICSA-26-055-03
Initial publicationFebruary 24, 2026 (4 CVEs)
Update AApril 2, 2026 (10 CVEs)
VendorGardyn Inc.
Affected productsGardyn Home Kit (Models 1.0, 2.0, 3.0, 4.0), Gardyn Studio (Models 1.0, 2.0)
Affected versionsMobile App <2.11.0; Cloud API <2.12.2026; Home Kit Firmware <master.622
SectorFood and Agriculture (CISA classification)
Registered devices (per researcher repository)138,160+
User records (per CVE-2026-28766)134,215
ResearcherMichael Groberman
CoordinatorCERT/CC (parent case VU#653116) and CISA
Status per CISA Update AAll ten CVEs remediated

The ten CVEs

CVETitleSeverity
CVE-2026-28766Missing Authentication: User Account EndpointCritical (9.3)
CVE-2025-1242Use of Hard-coded CredentialsCritical (9.1)
CVE-2025-29631OS Command InjectionCritical (9.1)
CVE-2026-25197Authorization Bypass via User-Controlled Key (IDOR)Critical (9.1)
CVE-2025-10681Hardcoded Azure Blob Storage Account KeyHigh (8.6)
CVE-2025-29628Cleartext Transmission of Sensitive InformationHigh (8.3)
CVE-2025-29629Use of Default CredentialsHigh (8.3)
CVE-2026-32646Missing Authentication: Admin Device ManagementHigh (7.5)
CVE-2026-28767Missing Authentication: Admin NotificationsMedium (5.3)
CVE-2026-32662Active Debug Code in ProductionMedium (5.3)

Endpoints documented as not requiring authentication

Per CISA advisory ICSA-26-055-03 (Update A), the absence of authentication is documented across multiple endpoint categories spanning customer-facing data, administrative functions, and development/test endpoints:

Per the CISA advisory, the lack of authentication is documented as a property of multiple endpoints rather than an isolated finding.

Detectability of access during the exposure window

Per the maintainer’s coordinated-disclosure repository, no authentication-level access logging existed on the affected endpoints during the exposure window; this is sourced to coordinated-disclosure correspondence and to a 2026-01-27 Gardyn customer-support response to a Personal Information Access Request, not to the CISA advisory text. When no access logging exists on an endpoint, unauthenticated access to that endpoint during the unlogged window is not observable in the vendor’s logs. See vendor public statements Item 9.

Attack chains documented in the maintainer’s repository

Per the maintainer’s repository, two attack chains are documented combining individual CVEs:

Disclosure timeline

Per the maintainer’s coordinated-disclosure repository, initial private vendor disclosure was on October 14, 2025, made by Michael Groberman in his self-identified capacity as a Gardyn customer with technical knowledge; CERT/CC was engaged on December 11, 2025 as an escalation after vendor silence. CISA published the initial advisory on February 24, 2026 with four CVEs and Update A on April 2, 2026 expanding to ten CVEs. See the full timeline and the coordinated disclosure process.

Primary sources