A critical vulnerability (CVE-2026-50086) has been identified in an IoT platform's identity and access management (IAM) system. The affected SSO gateway component improperly exposes bidirectional AES cryptographic operations using a platform signing key without requiring authentication. This creates a dual risk: (1) unauthorized access to cryptographic functions (CWE-306) and (2) exploitation of deprecated AES implementations (CWE-327). Attackers could leverage this to decrypt or forge cryptographic signatures, potentially compromising user credentials and device communications. The vulnerability affects the 'aqara-iam' IoT platform component, 'sso-gateway' authentication service, and associated 'aes-signing' cryptographic module. With a CVSS score of 10.0 (AV:N/AC:L/PR:N/UI:N/S:U/C:H), the flaw enables remote code execution and data exposure without user interaction. Immediate mitigation requires applying vendor-provided security patches, disabling exposed AES endpoints, and implementing network-level access controls to restrict gateway traffic. Organizations should also monitor for anomalous cryptographic operation patterns in affected systems. Given the risk of credential theft and system compromise, urgent remediation is strongly advised.