Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-62252: Homer creates admin account with default password 'sipcapture'
CVE-2026-62252 · published 2 days ago
Summary
When you install Homer and use its built‑in login, it automatically makes an administrator account named admin with the password sipcapture, and it does not force you to change it. Anyone who can reach the login page can sign in as an admin and control the system. Upgrade to version 11.0.283 or later, or manually change the admin password immediately after installation.
What to do
- Update github.com sipcapture to version 0.0.0-20260625091610-b2e942031ff8.
- Update sipcapture github.com/sipcapture/homer-app to version 0.0.0-20260625091610-b2e942031ff8.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | sipcapture | homer | < 11.0.283 |
| go | github.com | sipcapture |
< 0.0.0-20260625091610-b2e942031ff8 Fix: upgrade to 0.0.0-20260625091610-b2e942031ff8
|
| Go | sipcapture | github.com/sipcapture/homer-app |
< 0.0.0-20260625091610-b2e942031ff8 Fix: upgrade to 0.0.0-20260625091610-b2e942031ff8
|
Original advisory text
Homer: Hardcoded Default Admin Password 'sipcapture' With No Forced Change on First Login
Homer is open source telecom observability software. Prior to version 11.0.283, on every fresh Homer deployment using internal authentication, the bootstrap process automatically creates an `admin` account with the password `sipcapture` (stored as a legacy SHA-256 hex hash). There is no first-login forced-change mechanism. Any attacker who reaches the login endpoint immediately gains full administrative access. Version 11.0.283 patches the issue.
References
- https://github.com/sipcapture/homer/releases/tag/11.0.283
- https://github.com/sipcapture/homer/pull/838
- https://github.com/sipcapture/homer/commit/b2e942031ff8cd7435a244ebef306ee97d16b...
- https://github.com/advisories/GHSA-6xp5-7rcx-xfgx
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/62xxx/CVE-2026-62252... Vendor Advisory
- https://github.com/sipcapture/homer/security/advisories/GHSA-6xp5-7rcx-xfgx
- https://nvd.nist.gov/vuln/detail/CVE-2026-62252 Vendor Advisory
- https://github.com/sipcapture/homer Product
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Type
CWE-798Use of Hard-coded Credentials
Timeline
Published7 Oct 2026
Updated9 Oct 2026
First seen7 Oct 2026
Sources
CVE-2026-62252 · NVD
CVE-2026-62252 · MITRE
GHSA-6xp5-7rcx-xfgx · GHSA
CVE-2026-62252 · OSV
GHSA-6xp5-7rcx-xfgx · OSV
Track software like this
Free during beta