PT-2026-107592 · Homer · Homer
CVE-2026-62253
·
Published
2026-10-07
·
Updated
2026-10-07
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Homer versions prior to 11.0.283
Description
In default installations, the software fails to enforce authentication for protected API endpoints because the
jwtSecret variable defaults to an empty string. When this variable is empty, the JWTMiddleware() and JWTMiddlewareV4() functions immediately allow requests to proceed without validation. This results in all protected API endpoints under '/api/v1', '/api/v3', and '/api/v4' being completely unauthenticated, allowing unauthorized users to read or modify configuration, user data, database connections, and VoIP call data.Recommendations
Update to version 11.0.283.
As a temporary mitigation, ensure that a strong, non-empty value is configured for the
jwtSecret variable.Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Homer