CVE-2026-33359
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/05/2026
Last modified:
13/05/2026
Description
In Meari IoT Cloud alert image storage on Alibaba OSS (latest observed; storage service version not disclosed), motion snapshots are retrievable without authentication, signed URLs, or expiry enforcement. URLs function as direct object references and remain valid beyond expected operational windows.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH



