Meari's cloud backend for its internet-connected cameras and smart devices has two authorization holes that let any logged-in user peek at or tamper with gear that isn't theirs, and the vendor has no plans to fix it.
The flaws sit in the Meari IoT Cloud Platform OpenAPI Service, the backend that lets apps and integrators talk to Meari hardware. CVE-2026-101104 lets an authenticated user change the configuration of devices they do not own, with no check that they actually have permission, a bug rated 7.7 on the CVSS 3.1 scale. CVE-2026-96613 is worse in practice: anyone who knows a device's ID can pull its entire device shadow, including credentials, owner details, network data, and telemetry, without proving any relationship to that device. Both trace back to the same root cause, a missing-authorization flaw classified as CWE-862, and affect every version of the service. There is no patch and none is planned; the vendor, based in China, did not respond when the government tried to coordinate a fix.
That matters because this isn't a one-off camera bug, it's the authorization layer for a cloud service deployed worldwide across commercial and consumer hardware. Any device tied to this API is only as private as its ID number, which is not a secret. Security researcher Gabriel Adams gets credit for finding it, and there is no sign yet that anyone is exploiting it in the wild.
The advised fix is the usual one for abandoned IoT backends: keep the device off the open internet and hope the cloud API never gets found. For a service whose entire job is to be reachable from the internet, that is not really a fix at all.