HarborGuard / CVE
Back to search
CRITICALCVE-2026-28766Published Modified CNA icscert

CVE-2026-28766: Gardyn Cloud API Missing Authentication for Critical Function

A specific endpoint exposes all user account information for registered Gardyn users without requiring authentication.

Metrics

CVSS v4.0
9.2
Severity
CRITICAL
Fixed in
2.12.2026
Affected Products
1

Fix available

2.12.2026
Affected packages
  • Gardyn / Cloud API
    < 2.12.2026 (from 0)
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N