Bluehood · Bluehood · CVE-2026-49994
**Name of the Vulnerable Software and Affected Versions**
Bluehood versions prior to 0.7.1
**Description**
When `auth enabled` is active, session validation is only enforced on HTML page handlers. The `/api/*` endpoints, including `/api/device/{mac}/notes`, do not perform authentication checks. A network attacker with access to the dashboard port can read Bluetooth tracking data and modify application state, such as the heartbeat URL, prune retention, device groups, and per-device notes, without requiring a session cookie.
**Recommendations**
Update to version 0.7.1.