Mygardyn operates a cloud API platform where reported vulnerabilities concentrate on authentication and authorization handling, including missing authentication for critical functions, active debug code exposure, and authorization bypass through user-controlled keys. These patterns reflect the access-control and state-management complexity typical of API-driven services. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mygardyn over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-25197HIGH A specific endpoint allows authenticated users to pivot to other user profiles by modifying the id number in the API call. | Apr 3, 2026 | 8.1 | 29 | NO | NO |
CVE-2026-32646HIGH A specific administrative endpoint is accessible without proper authentication, exposing device management functions. | Apr 3, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-28766HIGH A specific endpoint exposes all user account information for registered Gardyn users without requiring authentication. | Apr 3, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-32662MEDIUM Development and test API endpoints are present that mirror production functionality. | Apr 3, 2026 | 5.3 | 18 | NO | NO |
CVE-2026-28767MEDIUM A specific administrative endpoint notifications is accessible without proper authentication. | Apr 3, 2026 | 5.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mygardyn.
Media articles that mention a CVE ID that affects a product developed by Mygardyn — matched by CVE ID, not by vendor name.