PT-2026-53283 · Unknown · Home Assistant

·

CVE-2026-55844

·

Published

2026-06-29

·

Updated

2026-06-30

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Home Assistant versions prior to 2025.5.0
Description The iOS companion app fails to respect the SSID allowlist for internal networks. While the app typically uses the Service Set Identifier (SSID)—the public name of a wireless network—to determine when to use the internal URL, it incorrectly falls back to the internal URL when no other URL is available. This behavior can lead to the exposure of the user's authentication token when the device is connected to an insecure network.
Recommendations Update to version 2025.5.0.

Exploit

Fix

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55844
GHSA-CM5V-547M-QH5H

Affected Products

Home Assistant