Description
The Azure Blob Storage container used for Gardyn device logs is publicly listable without authentication. A malicious user would be able to access any device log file available in the blob storage container.
Published: 2026-07-02
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A container in Microsoft Azure Blob Storage that holds Gardyn device logs is publicly listable without requiring authentication. This misconfigured permission – classified as CWE‑497 – allows a remote attacker to enumerate and download any log file stored in the container. The exposed logs may contain device configuration, state, and user activity information, thereby compromising confidentiality of the system.

Affected Systems

The flaw affects Gardyn products that use Azure Blob Storage for logging, including the Gardyn Cloud API, Gardyn Home Firmware, and Gardyn Studio Firmware. Specific affected product versions are not listed, so any deployment that has not yet applied the vendor’s updated infrastructure remains at risk until a fix is installed.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate risk. With the EPSS score of < 1% and the vulnerability currently not listed in CISA KEV, the likelihood of exploitation is low at present. Nevertheless, the attack vector is remote – an attacker can exploit the flaw from any internet‑connected location without credentials, making the vulnerability straightforward to leverage until the vendor releases and users apply the update.

Generated by OpenCVE AI on August 1, 2026 at 20:55 UTC.

Remediation

Vendor Solution

Gardyn states that IoT Hub deployed infrastructure has been updated to fix the listed vulnerabilities.


Vendor Workaround

Gardyn requests that users ensure their devices have Internet connectivity in order to automatically download needed firmware updates. Unconnected devices will automatically update when configured with a working Internet connection. Gardyn also recommends that users update their mobile application to the most recent version. The current versions of the Gardyn App and the Gardyn Home firmware can be checked in the Gardyn App. Further information on Gardyn security can be found here:  https://mygardyn.com/security/ Further customer support can be obtained from Gardyn at:  support@mygardyn.com mailto:support@mygardyn.com


OpenCVE Recommended Actions

  • Apply the latest firmware and IoT Hub infrastructure update to Gardyn devices via the mobile application.
  • Ensure all Gardyn devices remain connected to the internet so they can automatically download pending firmware updates; for offline devices, configure a working Internet connection and trigger the update.
  • Update the Gardyn mobile application to the most recent version to receive the latest security patches.

Generated by OpenCVE AI on August 1, 2026 at 20:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Gardyn
Gardyn gardyn Cloud Api
Gardyn gardyn Home Firmware
Gardyn gardyn Studio Firmware
Vendors & Products Gardyn
Gardyn gardyn Cloud Api
Gardyn gardyn Home Firmware
Gardyn gardyn Studio Firmware

Mon, 06 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 03 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Description The Azure Blob Storage container used for Gardyn device logs is publicly listable without authentication. A malicious user would be able to access any device log file available in the blob storage container.
Title Gardyn IoT Hub Exposure of Sensitive System Information to an Unauthorized Control Sphere
Weaknesses CWE-497
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:L'}


Subscriptions

Gardyn Gardyn Cloud Api Gardyn Home Firmware Gardyn Studio Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-07-06T15:44:18.370Z

Reserved: 2026-06-22T15:47:37.778Z

Link: CVE-2026-55726

cve-icon Vulnrichment

Updated: 2026-07-06T15:44:14.350Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-03T00:16:52.607

Modified: 2026-07-06T19:42:59.550

Link: CVE-2026-55726

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T21:00:08Z

Weaknesses
  • CWE-497

    Exposure of Sensitive System Information to an Unauthorized Control Sphere