CVE-2026-82452 CRITICAL

CVE-2026-82452: rust-iot-platform Authentication Bypass via Missing Request Guards

Vendor Iot-Ecology
Product rust-iot-platform
Weakness CWE-306 · Missing auth
Published August 29, 2026
Last update August 29, 2026

CVSS base score

9.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

rust-iot-platform through commit 5df942ab contains an authentication bypass vulnerability where most REST API routes lack authentication guards in their handler signatures. Unauthenticated attackers can create, update, list, retrieve, and delete user accounts by directly accessing unprotected endpoints without providing valid credentials.

Key dates

02Disclosure timeline

August 29, 2026 CVE published

Related vulnerabilities

04Related CVE