Security Advisory

CVE-2026-1201

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-01-22 21:52:01
Last updated 2026-01-29 16:51:31
Assigner icscert
State PUBLISHED

Description

An Authorization Bypass Through User-Controlled Key vulnerability in Hubitat Elevation home automation controllers prior to version 2.4.2.157 could allow a remote authenticated user to control connected devices outside of their authorized scope via client-side request manipulation.