CVE-2026-33359

HIGH

Meari unauthenticated alert image access in cloud object storage

Title source: cna
STIX 2.1

Description

In Meari IoT Cloud alert image storage on Alibaba OSS (latest observed; storage service version not disclosed), motion snapshots are retrievable without authentication, signed URLs, or expiry enforcement. URLs function as direct object references and remain valid beyond expected operational windows.

Scores

CVSS v3 7.5
EPSS 0.0029
EPSS Percentile 20.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (1)
Meari/Alibaba OSS Hosted April, 2026
Published May 11, 2026
Tracked Since May 11, 2026