PT-2026-107592 · Homer · Homer

CVE-2026-62253

·

Published

2026-10-07

·

Updated

2026-10-07

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Homer versions prior to 11.0.283
Description In default installations, the software fails to enforce authentication for protected API endpoints because the jwtSecret variable defaults to an empty string. When this variable is empty, the JWTMiddleware() and JWTMiddlewareV4() functions immediately allow requests to proceed without validation. This results in all protected API endpoints under '/api/v1', '/api/v3', and '/api/v4' being completely unauthenticated, allowing unauthorized users to read or modify configuration, user data, database connections, and VoIP call data.
Recommendations Update to version 11.0.283. As a temporary mitigation, ensure that a strong, non-empty value is configured for the jwtSecret variable.

Exploit

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-62253
GHSA-RQCC-94GV-WJM9

Affected Products

Homer