9.3
CVE-2026-50090
- EPSS 0.23%
- Veröffentlicht 12.06.2026 15:02:13
- Zuletzt bearbeitet 09.07.2026 17:41:07
- CVE-Watchlists
- Unerledigt
Aqara OAuth redirect_uri validation bypass
The Aqara Cloud OAuth Authorization Endpoint (open-cn.aqara.com/oauth/authorize) is vulnerable to a redirect bypass due to lax controls on domain matching, which is an instance of "CWE-1289: Improper Validation of Unsafe Equivalence in Input" and has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N (9.3 Critical).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Aqara ≫ Cloud Oauth Authorization Endpoint Version2026-04-20
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.23% | 0.136 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.1 | 2.8 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
|
| 44488dab-36db-4358-99f9-bc116477f914 | 9.3 | 2.8 | 5.8 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
|
CWE-1289 Improper Validation of Unsafe Equivalence in Input
The product receives an input value that is used as a resource identifier or other type of reference, but it does not validate or incorrectly validates that the input is equivalent to a potentially-unsafe value.
https://github.com/xn0tsa/theres-no-place-like-home
https://www.runzero.com/advisories/aqara-oauth-redirect-validation-bypass-cve-2026-50090