PT-2026-28606 · Unknown · Home Assistant

CVE-2026-34205

·

Published

2026-03-27

·

Updated

2026-06-19

CVSS v3.1

9.6

Critical

VectorAV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Home Assistant versions prior to 2026.03.02
Description Home Assistant is open source home automation software focused on local control and privacy. Home Assistant apps, when configured with host network mode, expose unauthenticated endpoints bound to the internal Docker bridge interface to the local network. This configuration does not restrict access to the app as intended, allowing any device on the same network to reach these endpoints without authentication.
Recommendations Update to Home Assistant Supervisor version 2026.03.02 or later.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-34205

Affected Products

Home Assistant