CVE-2026-13768: Gardyn Cloud API
Critical severity, CVSS 10.0. EPSS: 0.7% chance of exploitation in the next 30 days.
Gardyn devices expose a privileged iothubowner key. Access to this key will allow a malicious user to invoke an IoTHub Registry Manager function which returns connection information for all Gardyn Home Kit and Studio devices. Access to this key also allows a malicious user to execute arbitrary commands on a specific connected device and may allow the malicious user to pivot to other devices on the user's network.
Affected products
- Gardyn Gardyn Cloud API: before 2.12.2026 (fixed in 2.12.2026)
- Gardyn Gardyn Home Firmware
- Gardyn Gardyn Studio Firmware
Published 2026-07-03. Last modified 2026-07-06.