CVE-2026-1201
Severity CVSS v4.0:
CRITICAL
Type:
Unavailable / Other
Publication date:
22/01/2026
Last modified:
22/01/2026
Description
An Authorization Bypass Through User-Controlled Key vulnerability in Hubitat Elevation home automation controllers prior to version 2.4.2.157 could allow a remote authenticated user to control connected devices outside of their authorized scope via client-side request manipulation.
Impact
Base Score 4.0
9.40
Severity 4.0
CRITICAL



