Description
In igloohome Smart Lock Mobile App versions 3.2.3 and prior, an Inclusion of Sensitive Information in Source Code vulnerability could allow an unauthorized actor to access functions or backend services that were not sufficiently protected by authentication controls.
Published: 2026-07-28
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in igloohome Smart Lock Mobile Application arises from the inclusion of sensitive information in the source code, which permits an unauthenticated actor to invoke backend services that lack adequate authentication controls. The core impact is the potential for an attacker to manipulate or retrieve lock functions without authorization, thereby compromising the confidentiality and integrity of the lock system. The weakness is classified as CWE‑540, highlighting a configuration or deployment error where sensitive data is exposed in code.

Affected Systems

igloohome Smart Lock Mobile Application versions 3.2.3 and earlier are susceptible to this issue. Users operating these releases are at risk until they update to the patched version that implements enhanced backend access control mechanisms.

Risk and Exploitability

With a CVSS score of 6.9 the vulnerability is of moderate severity, while the EPSS score of less than 1% indicates a low probability of exploitation at present. The vulnerability is not listed in CISA KEV, implying no known active exploitation. The likely attack vector involves an attacker sending crafted requests to backend endpoints that are inadequately protected by authentication; such requests could be triggered remotely if network access is available. The vendor’s solution tightens authentication and authorization on backend services, removing the need for user interaction to mitigate the risk.

Generated by OpenCVE AI on August 3, 2026 at 14:23 UTC.

Remediation

Vendor Solution

igloohome has enhanced the access control mechanisms on backend services to ensure that only properly authenticated and authorized requests can interact with sensitive functionality. No user interaction is needed. For more information, contact igloohome (info@igloohome.com).


OpenCVE Recommended Actions

  • Upgrade the Smart Lock Mobile Application to the latest version that incorporates the enhanced access control fix.
  • Ensure the device firmware is current and that any ancillary services on the network are restricted to authenticated users only.
  • Enable or configure local monitoring or alarm notifications for unforeseen lock‑related activity to detect potential misuse early.

Generated by OpenCVE AI on August 3, 2026 at 14:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Igloohome
Igloohome smart Lock Mobile Application
Vendors & Products Igloohome
Igloohome smart Lock Mobile Application
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description In igloohome Smart Lock Mobile App versions 3.2.3 and prior, an Inclusion of Sensitive Information in Source Code vulnerability could allow an unauthorized actor to access functions or backend services that were not sufficiently protected by authentication controls.
Title Inclusion of sensitive information in source code in igloohome Smart Lock Mobile Application
Weaknesses CWE-540
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Igloohome Smart Lock Mobile Application
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-07-29T13:59:18.399Z

Reserved: 2026-07-22T13:40:37.456Z

Link: CVE-2026-16581

cve-icon Vulnrichment

Updated: 2026-07-29T13:58:45.559Z

cve-icon NVD

Status : Deferred

Published: 2026-07-28T21:17:28.070

Modified: 2026-07-30T14:12:18.697

Link: CVE-2026-16581

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T14:30:18Z

Weaknesses
  • CWE-540

    Inclusion of Sensitive Information in Source Code