PT-2026-69142 · Unknown · Home Assistant

CVE-2026-66060

·

Published

2026-08-07

·

Updated

2026-08-13

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Home Assistant versions prior to 2026.8.1
Description The Companion app processes tag links (NFC or QR) received via OS-level routing as physical scans without validating the source app or requesting user confirmation. This allows an untrusted application on the same device to forward arbitrary tags to Home Assistant, triggering associated automations silently and without user intervention.
Recommendations Update to version 2026.8.1.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-66060
GHSA-2XQV-HWRF-983F

Affected Products

Home Assistant