PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-28806 nerves-hub CVE debrief

CVE-2026-28806 is an Improper Authorization vulnerability in nerves-hub nerves_hub_web allowing cross-organization device control via device bulk actions and device update API. Missing authorization checks in the device bulk actions and device update API endpoints allow authenticated users to target devices belonging to other organizations and perform actions outside of their privilege level.

Vendor
nerves-hub
Product
nerves_hub_web
CVSS
CRITICAL 9.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-03-10
Original CVE updated
2026-05-27
Advisory published
2026-03-10
Advisory updated
2026-05-27

Who should care

Users of nerves_hub_web from version 1.0.0 before 2.4.0 should be aware of this vulnerability and take immediate action to protect their systems. This vulnerability allows attackers to interfere with firmware updates, access device functionality exposed by the platform, or disrupt device connectivity. In environments where additional features such as remote console access are enabled, this could lead to full compromise of affected devices.

Technical summary

The vulnerability exists due to missing authorization checks in the device bulk actions and device update API endpoints. This allows authenticated users to target devices belonging to other organizations and perform actions outside of their privilege level. An attacker can select devices outside of their organization by manipulating device identifiers and perform management actions on them, such as moving them to products they control.

Defensive priority

High

Recommended defensive actions

  • Apply the patches provided by the vendor
  • Restrict access to the device bulk actions and device update API endpoints
  • Monitor for suspicious activity on the network
  • Implement additional security measures such as multi-factor authentication
  • Regularly review and update access controls

Evidence notes

The CVE record was published on 2026-03-10T22:16:18.420Z and was last modified on 2026-05-27T13:47:15.800Z. The NVD entry is currently Analyzed. Evidence is limited to public CVE and NVD information; defenders should verify affected deployments, scope, and vendor guidance with additional sources.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-28806 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-28806

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-28806 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-28806

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://cna.erlef.org/cves/CVE-2026-28806.html

    6b3ad84c-e1a6-4bf7-a703-f496b71e49db - Third Party Advisory, Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://github.com/nerves-hub/nerves_hub_web/commit/1f69c9d595684a4650c3ac702f3dc7c5bcd7526c

    6b3ad84c-e1a6-4bf7-a703-f496b71e49db - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://github.com/nerves-hub/nerves_hub_web/security/advisories/GHSA-f8fr-mccc-xvcx

    6b3ad84c-e1a6-4bf7-a703-f496b71e49db - Patch, Vendor Advisory

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://osv.dev/vulnerability/EEF-CVE-2026-28806

    6b3ad84c-e1a6-4bf7-a703-f496b71e49db - Third Party Advisory, Patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.