CVE-2026-1201: Hubitat Elevation c3

Critical severity, CVSS 9.4. EPSS: 0.5% chance of exploitation in the next 30 days.

An Authorization Bypass Through User-Controlled Key vulnerability in Hubitat Elevation home automation controllers prior to version 2.4.2.157 could allow a remote authenticated user to control connected devices outside of their authorized scope via client-side request manipulation.

Affected products

  • Hubitat Elevation c3: before 2.4.2.157 (fixed in 2.4.2.157)
  • Hubitat Elevation c4: before 2.4.2.157 (fixed in 2.4.2.157)
  • Hubitat Elevation c5: before 2.4.2.157 (fixed in 2.4.2.157)
  • Hubitat Elevation c7: before 2.4.2.157 (fixed in 2.4.2.157)
  • Hubitat Elevation c8: before 2.4.2.157 (fixed in 2.4.2.157)
  • Hubitat Elevation c8 Pro: before 2.4.2.157 (fixed in 2.4.2.157)

Published 2026-01-22. Last modified 2026-06-17.