A critical vulnerability, CVE-2026-13768, has been identified in Gardyn Home Kit and Studio devices. The flaw stems from an exposed privileged iothubowner key, which allows attackers to invoke IoTHub Registry Manager functions. This enables retrieval of connection details for all affected devices and execution of arbitrary commands on targeted systems. Successful exploitation could lead to full device control and lateral movement within the victim's network. All Gardyn appliance users are affected. The CVSS score of 10.0 reflects the high risk of remote code execution and network pivoting capabilities. Immediate action is required: apply vendor-provided firmware updates, restrict access to exposed keys, and monitor for anomalous device behavior. Network segmentation and strict access controls should be enforced to mitigate potential exploitation until patches are deployed.