Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-62253: Homer allows anyone to access API when secret is empty

CVE-2026-62253 · published 2 days ago
Summary

The open‑source Homer monitoring tool leaves its API endpoints open if the JWT secret is not set, which is the default on a fresh install. This means anyone can call the protected /api/v1, /api/v3 and /api/v4 functions without authentication. Upgrade to version 11.0.283 or configure a non‑empty secret to secure the APIs.

What to do
  • Update github.com sipcapture to version 0.0.0-20260625093330-5e90809657c9.
  • Update sipcapture github.com/sipcapture/homer-app to version 0.0.0-20260625093330-5e90809657c9.
Affected software
Ecosystem VendorProductAffected versions
– sipcapture homer < 11.0.283
go github.com sipcapture < 0.0.0-20260625093330-5e90809657c9
Fix: upgrade to 0.0.0-20260625093330-5e90809657c9
Go sipcapture github.com/sipcapture/homer-app < 0.0.0-20260625093330-5e90809657c9
Fix: upgrade to 0.0.0-20260625093330-5e90809657c9
Original advisory text
Homer: Complete Authentication Bypass When coordinator.jwt.secret Is Empty (Default)
Homer is open source telecom observability software. Prior to version 11.0.283, both JWT middleware functions (`JWTMiddleware` and `JWTMiddlewareV4`) immediately return `next(c)` when `jwtSecret == ""`. The JWT secret defaults to an empty string. On a default installation, all protected API endpoints under `/api/v1`, `/api/v3`, and `/api/v4` are completely unauthenticated. Version 11.0.283 patches the issue.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.8 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-306Missing Authentication for Critical Function
Timeline
Published7 Oct 2026
Updated10 Oct 2026
First seen7 Oct 2026
Track software like this
Free during beta