CVE 7.5 HIGH

Meari unauthenticated alert image access in cloud object storage_CVE-2026-33359

7.5 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Description

In Meari IoT Cloud alert image storage on Alibaba OSS (latest observed; storage service version not disclosed), motion snapshots are retrievable without authentication, signed URLs, or expiry enforcement. URLs function as direct object references and remain valid beyond expected operational windows.

Basic Information

ID CVE-2026-33359
Source runZero
Published May 11, 2026 at 16:03

Affected Product

Vendor Meari
Product Alibaba OSS Hosted
Version April, 2026
Affected Versions Meari Alibaba OSS Hosted April, 2026

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.