A vulnerability classified as critical was found in Hubitat Elevation C3, Elevation C4, Elevation C5, Elevation C7, Elevation C8 and Elevation C8 pro. The affected element is an unknown function. Such manipulation leads to authorization bypass.

This vulnerability is traded as CVE-2026-1201. The attack may be launched remotely. There is no exploit available.

Upgrading the affected component is advised.