Mygardyn: community verdicts
5 notable / known-exploited Mygardyn CVEs the community has triaged.
ⓘ Not an exhaustive list: we focus on the findings that matter (exploited / notable). For every Mygardyn CVE, see NVD ↗.
- CVE-2026-32646HIGH 7.5Real · low riskEPSS 0%
A specific administrative endpoint is accessible without proper authentication, exposing device management functions.
- CVE-2026-28766CRIT 9.3Real · low riskEPSS 0%
A specific endpoint exposes all user account information for registered Gardyn users without requiring authentication.
- CVE-2026-28767MED 5.3EPSS 0%
A specific administrative endpoint notifications is accessible without proper authentication.
- CVE-2026-32662MED 5.3EPSS 0%
Development and test API endpoints are present that mirror production functionality.
- CVE-2026-25197CRIT 9.1Real · low riskEPSS 0%
A specific endpoint allows authenticated users to pivot to other user profiles by modifying the id number in the API call.