PT-2026-107591 · Homer · Homer

CVE-2026-62252

·

Published

2026-10-07

·

Updated

2026-10-07

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Homer versions prior to 11.0.283
Description In fresh deployments using internal authentication, the bootstrap process automatically creates an admin account with a hard-coded password sipcapture. This password is stored as a legacy SHA-256 hex hash, and the system lacks a mechanism to force a password change upon the first login. An attacker can gain full administrative access by accessing the /api/v3/auth endpoint using these default credentials. The issue is rooted in the EnsureBootstrapAdminUser() function, which inserts the default credentials if no admin user exists, and the legacySHA256HexEqual function, which allows the use of the legacy hash.
Recommendations Update to version 11.0.283.

Exploit

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-62252
GHSA-6XP5-7RCX-XFGX

Affected Products

Homer