Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-49994: Bluehood lets anyone change settings via API
CVE-2026-49994 · published 4 days ago
Summary
In versions before 0.7.1, Bluehood's web interface required login only for its web pages, not for its API endpoints. This allowed anyone on the same network to view Bluetooth data and alter settings such as device groups, notes, and the heartbeat URL without a valid session. Update to version 0.7.1 or later to enforce authentication on all API calls.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| dannymcc | bluehood | < 0.7.1 |
Original advisory text
Bluehood: Missing authentication on Bluehood API routes when web auth is enabled
Bluehood monitors local bluetooth activity. Prior to version 0.7.1, when auth_enabled is set in Bluehood, only the HTML page handlers enforced session validation. The /api/* handlers (settings, devices, groups, per-device endpoints including /api/device/{mac}/notes) called no auth check at all. A network attacker reachable on the dashboard port could read Bluetooth tracking data and modify application state — including the heartbeat URL, prune retention, device groups, and per-device notes — without a session cookie. This issue has been patched in version 0.7.1.
References
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/49xxx/CVE-2026-49994... Vendor Advisory
- https://github.com/dannymcc/bluehood/commit/401479938c0deb1f6f6847d442f98a2d03ef... Patch
- https://github.com/dannymcc/bluehood/releases/tag/v0.7.1 URL
- https://nvd.nist.gov/vuln/detail/CVE-2026-49994 Vendor Advisory
- https://github.com/dannymcc/bluehood/security/advisories/GHSA-qj2j-wcg3-74jw Vendor Advisory
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Type
CWE-306Missing Authentication for Critical Function
CWE-862Missing Authorization
Timeline
Published28 Sep 2026
Updated2 Oct 2026
First seen28 Sep 2026
Track software like this
Free during beta