Description
An Authorization Bypass Through User-Controlled Key vulnerability in Hubitat Elevation home automation controllers prior to version 2.4.2.157 could allow a remote authenticated user to control connected devices outside of their authorized scope via client-side request manipulation.
Problem types
CWE-639 Authorization Bypass Through User-Controlled Key
Product status
Any version before 2.4.2.157
Any version before 2.4.2.157
Any version before 2.4.2.157
Any version before 2.4.2.157
Any version before 2.4.2.157
Any version before 2.4.2.157
Credits
Aaron 'theHastyOne' Hasty of Ostrich Lab reported this vulnerability to CISA.
References
www.cisa.gov/news-events/ics-advisories/icsa-26-022-06
ostrichlab.io/research-blog/?post=hubitat_writeup