PT-2026-48914 · Aqara · Aqara Cloud

·

CVE-2026-50090

·

Published

2026-06-12

·

Updated

2026-06-13

CVSS v3.1

9.3

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Aqara Cloud (affected versions not specified)
Description The OAuth Authorization Endpoint "open-cn.aqara.com/oauth/authorize" is subject to a redirect bypass caused by improper validation of unsafe equivalence in input. This flaw allows for domain matching bypass, which can be leveraged to facilitate phishing attacks and session theft.
Recommendations Disable OAuth integration until a fix is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-50090

Affected Products

Aqara Cloud