Description
The Azure Blob Storage container used for Gardyn device logs is publicly listable without authentication. A malicious user would be able to access any device log file available in the blob storage container.
Published: 2026-07-02
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is that a container in Microsoft Azure Blob Storage used for Gardyn device logs is publicly listable without authentication. This is an example of CWE-497: Misconfigured Permissions. Because no access controls are enforced, a malicious actor can enumerate and download any log file that is stored in the container. This leakage of log data can expose configuration, device state, or user activity information, thereby compromising confidentiality.

Affected Systems

The flaw affects Gardyn products that use Azure Blob Storage for logging, including the Gardyn Cloud API, Gardyn Home Firmware, and Gardyn Studio Firmware. Any current deployment of these products that has not applied the updated infrastructure is susceptible until the vendor releases a fix.

Risk and Exploitability

With a CVSS score of 6.9 the risk is moderate. The likely attack vector is remote internet access to the publicly reachable Azure Blob Storage container, requiring no authentication and allowing straightforward exploitation. The EPSS score of < 1% and absence from the CISA KEV catalog suggest a low probability of exploitation at present, but the vulnerability remains exploitable from any remote location until the vendor’s update is deployed.

Generated by OpenCVE AI on July 21, 2026 at 10:29 UTC.

Remediation

Vendor Solution

Gardyn states that IoT Hub deployed infrastructure has been updated to fix the listed vulnerabilities.


Vendor Workaround

Gardyn requests that users ensure their devices have Internet connectivity in order to automatically download needed firmware updates. Unconnected devices will automatically update when configured with a working Internet connection. Gardyn also recommends that users update their mobile application to the most recent version. The current versions of the Gardyn App and the Gardyn Home firmware can be checked in the Gardyn App. Further information on Gardyn security can be found here:  https://mygardyn.com/security/ Further customer support can be obtained from Gardyn at:  support@mygardyn.com mailto:support@mygardyn.com


OpenCVE Recommended Actions

  • Upgrade Gardyn Home firmware and Gardyn Studio firmware to the latest versions available through the Gardyn mobile app, applying the updated IoT Hub infrastructure fix.
  • Ensure all devices are connected to the internet so they can automatically download and install pending firmware updates; offline devices should reconfigure a working Internet connection to trigger the update.
  • Install the latest Gardyn mobile application from the official source to receive the most recent firmware and security updates.

Generated by OpenCVE AI on July 21, 2026 at 10:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 03 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Description The Azure Blob Storage container used for Gardyn device logs is publicly listable without authentication. A malicious user would be able to access any device log file available in the blob storage container.
Title Gardyn IoT Hub Exposure of Sensitive System Information to an Unauthorized Control Sphere
Weaknesses CWE-497
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-07-06T15:44:18.370Z

Reserved: 2026-06-22T15:47:37.778Z

Link: CVE-2026-55726

cve-icon Vulnrichment

Updated: 2026-07-06T15:44:14.350Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T10:30:04Z

Weaknesses
  • CWE-497

    Exposure of Sensitive System Information to an Unauthorized Control Sphere