CVE-2026-71278: IoT-Ecology Rust-IoT-Platform
Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.
rust-iot-platform allows creating a "calc rule" via POST /calc-rule/create (api/src/controller/calc_rule_router.rs) containing an arbitrary field. This route does not take the AuthToken request guard used elsewhere in the application, making it reachable without authentication.
Affected products
- IoT-Ecology Rust-IoT-Platform: any version
Published 2026-08-05. Last modified 2026-08-26.