PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-50087 Aqara CVE debrief

CVE-2026-50087 is a cross-origin request sharing vulnerability, classified as CWE-942: Permissive Cross-domain Policy with Untrusted Domains. The vulnerability affects the Aqara IAM/SSO gateway (gw-builder.aqara.com) and has a CVSS score of 8.2 (High) with the following vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N.

Vendor
Aqara
Product
Aqara IAM/SSO Gateway
CVSS
HIGH 8.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-12
Original CVE updated
2026-07-09
Advisory published
2026-06-12
Advisory updated
2026-07-09

Who should care

Security teams and administrators responsible for the Aqara IAM/SSO gateway should be aware of this vulnerability and take necessary actions to mitigate it.

Technical summary

The Aqara IAM/SSO gateway exhibits a cross-origin request sharing vulnerability, which allows an attacker to make unauthorized requests on behalf of the user. This vulnerability requires user interaction (UI:R) and can result in high confidentiality impact (C:H), low integrity impact (I:L), and no availability impact (A:N).

Defensive priority

High

Recommended defensive actions

  • Review and update the Aqara IAM/SSO gateway configuration to restrict cross-origin requests.
  • Implement proper cross-origin resource sharing (CORS) policies.
  • Monitor the gateway for suspicious activity.

Evidence notes

The CVE record and NVD detail pages provide additional information about the vulnerability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-50087 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-50087

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-50087 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-50087

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/xn0tsa/theres-no-place-like-home

    44488dab-36db-4358-99f9-bc116477f914

  • Source reference

    Unverified legacy reference

    URL: https://www.runzero.com/advisories/aqara-iam-sso-cors-cve-2026-50087

    44488dab-36db-4358-99f9-bc116477f914

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.