CVE-2026-1201

Severity CVSS v4.0:
CRITICAL
Type:
Unavailable / Other
Publication date:
22/01/2026
Last modified:
22/01/2026

Description

An Authorization Bypass Through User-Controlled Key vulnerability in Hubitat Elevation home automation controllers prior to version 2.4.2.157 could allow a remote authenticated user to control connected devices outside of their authorized scope via client-side request manipulation.

References to Advisories, Solutions, and Tools