Aqara Cloud OAuth Flaw (CVE-2026-50090): What It Is and Whether You Are Affected
CVE-2026-50090 is a CVSS 9.3 OAuth redirect bypass in Aqara’s cloud. If you run Zigbee2MQTT, ZHA, or local HomeKit, you are not in scope. Here is why.
CVE-2026-50090 is a CVSS 9.3 OAuth redirect bypass in Aqara’s cloud. If you run Zigbee2MQTT, ZHA, or local HomeKit, you are not in scope. Here is why.
Set up the Aqara Dimmer Switch H2 (KD-R01D) with Zigbee2MQTT and Home Assistant. Covers the firmware switch, decoupled mode, smart bulb automations, and known bugs.
Set up the Aqara Motion and Illuminance Sensor T1 (RTCGQ12LM) in Home Assistant via Zigbee2MQTT — no hub, no cloud. Pairing, timeout, lux automations.
Set up the Aqara JY-GZ-01AQ smoke detector in Home Assistant via Zigbee2MQTT: pairing, entities, the firmware v21 regression, and known bugs.
Set up the Aqara JT-BZ-01AQ natural gas detector in Home Assistant via Zigbee2MQTT: pairing, all 10 entities, sensitivity, automations.
Pair the Aqara Wireless Switch E1 with Zigbee2MQTT, build reliable HA automations, and fix the WXKG15LM binding gotcha that hides left from right.
Pair the Aqara LED Bulb T2 with Zigbee2MQTT and Home Assistant for fully local control. Updated for Z2M 2.7.2 native support, no external converter.
VLAN isolation breaks Aqara hub discovery and Xiaomi Miio control. The fix is mDNS reflection, outbound NAT, and firewall rules in the right order.
Switch the Aqara FP300 from Thread to Zigbee, pair it in Zigbee2MQTT, and run it locally in Home Assistant with the full configuration entity set.
FP2 and FP300 are very different sensors with very different HA integration paths. The honest comparison for a local-first Home Assistant setup.