8.2
CVE-2026-50088
- EPSS 0.22%
- Veröffentlicht 12.06.2026 15:01:49
- Zuletzt bearbeitet 09.07.2026 17:43:01
- CVE-Watchlists
- Unerledigt
Aqara Developer Portal cross-origin resource sharing
The Aqara Developer Portal (developer.aqara.com) and shared test environments (developer-test.aqara.com, aiot-test.aqara.com) exhibit cross-origin request sharing, which is an instance of "CWE-942: Permissive Cross-domain Policy with Untrusted Domains," and has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N (8.2 High).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Aqara ≫ Developer Portal Version2026-04-20
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.22% | 0.119 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.7 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
|
| 44488dab-36db-4358-99f9-bc116477f914 | 8.2 | 2.8 | 4.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
|
CWE-942 Permissive Cross-domain Security Policy with Untrusted Domains
The product uses a web-client protection mechanism such as a Content Security Policy (CSP) or cross-domain policy file, but the policy includes untrusted domains with which the web client is allowed to communicate.
https://github.com/xn0tsa/theres-no-place-like-home
https://www.runzero.com/advisories/aqara-dev-portal-cors-cve-2026-50088