Impact
A missing authentication check in the Public Invitation‑Code Redemption Endpoint allows a remote attacker to redeem arbitrary invitation codes by manipulating the code argument, which can lead to unauthorized account access or service abuse. The flaw is an Authentication Failure and Missing Authentication weakness, which can compromise the confidentiality and integrity of the system.
Affected Systems
the‑momentum open‑wearables version 0.6.2 and earlier, specifically the redeem_invitation_code function in backend/app/api/routes/v1/user_invitation_code.py, exposes this endpoint to all users.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity, and the lack of authentication on a publicly reachable endpoint makes it easily exploitable. Although no EPSS score is currently available and the vulnerability is not listed in the CISA KEV catalog, the remote exploitability and absence of mitigation measures create a significant risk to affected deployments.
OpenCVE Enrichment