← Zurück zur CVE-Suche

CVE-2026-33359

Alibaba OSS

Beschreibung

In Meari IoT Cloud alert image storage on Alibaba OSS (latest observed; storage service version not disclosed), motion snapshots are retrievable without authentication, signed URLs, or expiry enforcement. URLs function as direct object references and remain valid beyond expected operational windows.

CVSS 7.5EPSS 0.293%Risiko 0.77
Quelle öffnen
Veröffentlicht
2026-05-11 17:16:30
Betroffene Versionen
unknown
Typ
Core software
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N