PT-2026-77313 · Home Assistant · Blueprint-Studio

CVE-2026-53453

·

Published

2026-08-18

·

Updated

2026-08-19

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Blueprint Studio versions prior to 2.5.2
Description Blueprint Studio fails to consistently enforce the admin-only authorization boundary on its backend, allowing any authenticated Home Assistant user to access actions intended for administrators. This issue affects several surfaces, including the backend API, upload API, stream routes, terminal WebSocket, and Blueprint Studio WebSocket subscriptions. Specifically, the call service, render template, and global replace functions, as well as file and stream access paths, upload handling, and terminal helpers, are exposed. An attacker with non-admin privileges could invoke arbitrary Home Assistant services, expose system state via templates, modify configuration files, access streamed or downloaded content, upload files, or access terminal-related helpers, potentially compromising the confidentiality, integrity, and availability of the installation.
Recommendations Update to version 2.5.2.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53453
GHSA-PPWQ-CH6X-936G

Affected Products

Blueprint-Studio