A critical vulnerability (CVE-2026-50086) has been identified in an IoT platform's identity and access management (IAM) system. The affected SSO gateway component improperly exposes bidirectional AES cryptographic operations using a platform signing key without requiring authentication. This creates a dual risk: (1) unauthorized access to cryptographic functions (CWE-306) and (2) exploitation of deprecated AES implementations (CWE-327). Attackers could leverage this to decrypt or forge cryptographic signatures, potentially compromising user credentials and device communications. The vulnerability affects the 'aqara-iam' IoT platform component, 'sso-gateway' authentication service, and associated 'aes-signing' cryptographic module. With a CVSS score of 10.0 (AV:N/AC:L/PR:N/UI:N/S:U/C:H), the flaw enables remote code execution and data exposure without user interaction. Immediate mitigation requires applying vendor-provided security patches, disabling exposed AES endpoints, and implementing network-level access controls to restrict gateway traffic. Organizations should also monitor for anomalous cryptographic operation patterns in affected systems. Given the risk of credential theft and system compromise, urgent remediation is strongly advised.
CRITICAL
CVSS 10.0
CVE-2026-50086
2026-08-12
Critical AES Authentication Flaw in Aqara IAM/SSO Gateway (CVE-2026-50086)
A critical vulnerability in an IoT platform's authentication gateway allows unauthenticated AES cryptographic operations, exposing signing keys. CVSS 10.0. Immediate patching required to prevent potential data compromise.