← Terug naar overzicht

A missing authentication vulnerability was identified in the-momentum open-wearables project up to version 0.6.2. The flaw resides in the redeem_invitation_code function within backend/app/api/routes/v1/user_invitation_code.py, part of the Public Invitation-Code Redemption Endpoint. By manipulating the 'code' argument, an unauthenticated remote attacker can exploit the endpoint without proper authentication checks. This allows unauthorized access to invitation code redemption functionality. The vulnerability is remotely exploitable, increasing its risk surface. The project maintainers were notified via an issue report but have not responded or issued a fix as of the time of disclosure. The lack of response raises concerns about the project's security posture and patch availability. Users of open-wearables up to version 0.6.2 are potentially exposed. No patch or workaround has been officially released.

Affected products

  • the-momentum open-wearables up to 0.6.2

Related CVE's

  • CVE-2026-78154

Categories

  • Identity & Access
  • Mobile & IoT
  • Web Technologies