PT-2026-28606 · Unknown · Home Assistant

CVE-2026-34205

·

Publicado

2026-03-27

·

Atualizado

2026-06-19

CVSS v3.1

9.6

Crítica

VetorAV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Home Assistant versions prior to 2026.03.02
Description Home Assistant is open source home automation software focused on local control and privacy. Home Assistant apps, when configured with host network mode, expose unauthenticated endpoints bound to the internal Docker bridge interface to the local network. This configuration does not restrict access to the app as intended, allowing any device on the same network to reach these endpoints without authentication.
Recommendations Update to Home Assistant Supervisor version 2026.03.02 or later.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-34205

Produtos afetados

Home Assistant