PatchSiren cyber security CVE debrief
CVE-2026-28806 nerves-hub CVE debrief
CVE-2026-28806 is an Improper Authorization vulnerability in nerves-hub nerves_hub_web allowing cross-organization device control via device bulk actions and device update API. Missing authorization checks in the device bulk actions and device update API endpoints allow authenticated users to target devices belonging to other organizations and perform actions outside of their privilege level.
- Vendor
- nerves-hub
- Product
- nerves_hub_web
- CVSS
- CRITICAL 9.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-03-10
- Original CVE updated
- 2026-05-27
- Advisory published
- 2026-03-10
- Advisory updated
- 2026-05-27
Who should care
Users of nerves_hub_web from version 1.0.0 before 2.4.0 should be aware of this vulnerability and take immediate action to protect their systems. This vulnerability allows attackers to interfere with firmware updates, access device functionality exposed by the platform, or disrupt device connectivity. In environments where additional features such as remote console access are enabled, this could lead to full compromise of affected devices.
Technical summary
The vulnerability exists due to missing authorization checks in the device bulk actions and device update API endpoints. This allows authenticated users to target devices belonging to other organizations and perform actions outside of their privilege level. An attacker can select devices outside of their organization by manipulating device identifiers and perform management actions on them, such as moving them to products they control.
Defensive priority
High
Recommended defensive actions
- Apply the patches provided by the vendor
- Restrict access to the device bulk actions and device update API endpoints
- Monitor for suspicious activity on the network
- Implement additional security measures such as multi-factor authentication
- Regularly review and update access controls
Evidence notes
The CVE record was published on 2026-03-10T22:16:18.420Z and was last modified on 2026-05-27T13:47:15.800Z. The NVD entry is currently Analyzed. Evidence is limited to public CVE and NVD information; defenders should verify affected deployments, scope, and vendor guidance with additional sources.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-28806 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-28806
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-28806 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-28806
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://cna.erlef.org/cves/CVE-2026-28806.html
6b3ad84c-e1a6-4bf7-a703-f496b71e49db - Third Party Advisory, Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/nerves-hub/nerves_hub_web/commit/1f69c9d595684a4650c3ac702f3dc7c5bcd7526c
6b3ad84c-e1a6-4bf7-a703-f496b71e49db - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/nerves-hub/nerves_hub_web/security/advisories/GHSA-f8fr-mccc-xvcx
6b3ad84c-e1a6-4bf7-a703-f496b71e49db - Patch, Vendor Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://osv.dev/vulnerability/EEF-CVE-2026-28806
6b3ad84c-e1a6-4bf7-a703-f496b71e49db - Third Party Advisory, Patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.