Vulnerability record

CVE-2026-93289

Severity: CriticalExploitation: No known exploitation

Patch status

No official fix confirmed yet

Until a fix ships, follow the vendor's mitigations, limit exposure of affected systems, and watch this record for a patch.

Description

The affected products are vulnerable to command injection attack that could allow an unauthenticated attacker to execute system commands during the pairing process.

Source: NIST National Vulnerability Database. Official vulnerability data, reproduced as published.

Intelligence timeline

Developments from the last 30 days, newest first.

  1. CVSS scoredUpdate

    CVE-2026-93289 scored CVSS 9.0

    Basis: NIST National Vulnerability Database

  2. Disclosed

    Eufy Omni C20, Omni X10 Pro

    Basis: CISA Cybersecurity Advisories (government advisory)

Coverage

Severity: CriticalAction: Patch

Eufy Omni C20, Omni X10 Pro

Patch

Apply the vendor's security update for the affected products.

References

  • cisa.gov https://www.cisa.gov/news-events/ics-advisories/icsa-26-267-02