Gardyn Security Incident

← All CVEs in ICSA-26-055-03

CVE-2026-28766

Missing Authentication: User Account Endpoint

CVECVE-2026-28766
SeverityCritical (9.3)
Weakness (CWE)CWE-306: Missing Authentication for Critical Function
Affected componentsCloud API <2.12.2026
VendorGardyn Inc.
Affected productsGardyn Home Kit Models 1.0, 2.0, 3.0, 4.0; Gardyn Studio Models 1.0, 2.0
SectorFood and Agriculture (CISA classification)
Status per CISA Update ARemediated
CoordinatorCERT/CC (parent case VU#653116) and CISA

What is documented

Per the CISA advisory, an unauthenticated cloud API endpoint (/api/users) exposed records described in the advisory as “all user account information.” Per the researcher’s coordinated-disclosure repository, the records included names, email addresses, phone numbers, physical addresses, and the last_four partial payment-card field for approximately 134,215 customers. Per the researcher’s repository, the vendor stated to CISA that no access logging existed on the affected endpoint during the exposure window.

Primary sources

Mitigation per CISA Update A

Per CISA Update A (April 2, 2026), this CVE is remediated. The fix versions stated by CISA are: Gardyn mobile application 2.11.0 or later; Gardyn cloud API 2.12.2026 or later; Home Kit firmware master.622 or later. See the CISA advisory and the how to update page.

← All CVEs in ICSA-26-055-03