CVE-2026-13768: Gardyn Cloud API

Critical severity, CVSS 10.0. EPSS: 0.7% chance of exploitation in the next 30 days.

Gardyn devices expose a privileged iothubowner key. Access to this key will allow a malicious user to invoke an IoTHub Registry Manager function which returns connection information for all Gardyn Home Kit and Studio devices. Access to this key also allows a malicious user to execute arbitrary commands on a specific connected device and may allow the malicious user to pivot to other devices on the user's network.

Affected products

  • Gardyn Gardyn Cloud API: before 2.12.2026 (fixed in 2.12.2026)
  • Gardyn Gardyn Home Firmware
  • Gardyn Gardyn Studio Firmware

Published 2026-07-03. Last modified 2026-07-06.