HarborGuard / CVE
Back to search
CRITICALCVE-2026-25197Published Modified CNA icscert

CVE-2026-25197: Gardyn Cloud API Authorization Bypass Through User-Controlled Key

A specific endpoint allows authenticated users to pivot to other user profiles by modifying the id number in the API call.

Metrics

CVSS v4.0
9.3
Severity
CRITICAL
Fixed in
2.12.2026
Affected Products
1

Fix available

2.12.2026
Affected packages
  • Gardyn / Cloud API
    < 2.12.2026 (from 0)
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N