CVE-2026-13768 CRITICAL

CVE-2026-13768: Gardyn IoT Hub Use of Hard-coded Credentials

Vendor Gardyn
Product Gardyn Home Firmware
Weakness CWE-798 · Hardcoded credentials
Published July 2, 2026
Last update July 6, 2026

CVSS base score

10.0/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L

What the vulnerability does

01Description

Gardyn devices expose a privileged iothubowner key. Access to this key will allow a malicious user to invoke an IoTHub Registry Manager function which returns connection information for all Gardyn Home Kit and Studio devices. Access to this key also allows a malicious user to execute arbitrary commands on a specific connected device and may allow the malicious user to pivot to other devices on the user's network.

Key dates

02Disclosure timeline

July 2, 2026 CVE published
July 6, 2026 Record updated

Related vulnerabilities

04Related CVE