CVE-2026-28767 | Gardyn Cloud API up to 2.12.2025 Administrative Endpoint missing authentication (icsa-26-055-03 / EUVD-2026-18841)
A vulnerability was found in Gardyn Cloud API up to 2.12.2025. It has been declared as critical. Affected is an unknown function of the component Administrative Endpoint. The manipulation results in missing authentication.
This vulnerability is known as CVE-2026-28767. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.