# CVE-2026-16581

## Summary

- **CVE ID:** CVE-2026-16581
- **Severity:** MEDIUM
- **CVSS Score:** 6.9 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-540
- **Published:** Jul 28, 2026
- **Last Modified:** Jul 29, 2026

## Description

In igloohome Smart Lock Mobile App versions 3.2.3 and prior, an Inclusion of Sensitive Information in Source Code vulnerability could allow an unauthorized actor to access functions or backend services that were not sufficiently protected by authentication controls.

## Affected Products

- igloohome — Smart Lock Mobile Application (Version 3.2.3)

## References

- [CNA](https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-06)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.22%
- **EPSS Percentile:** 13.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._