Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-62253: Homer allows anyone to access API when secret is empty
CVE-2026-62253 · published 2 days ago
Summary
The open‑source Homer monitoring tool leaves its API endpoints open if the JWT secret is not set, which is the default on a fresh install. This means anyone can call the protected /api/v1, /api/v3 and /api/v4 functions without authentication. Upgrade to version 11.0.283 or configure a non‑empty secret to secure the APIs.
What to do
- Update github.com sipcapture to version 0.0.0-20260625093330-5e90809657c9.
- Update sipcapture github.com/sipcapture/homer-app to version 0.0.0-20260625093330-5e90809657c9.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | sipcapture | homer | < 11.0.283 |
| go | github.com | sipcapture |
< 0.0.0-20260625093330-5e90809657c9 Fix: upgrade to 0.0.0-20260625093330-5e90809657c9
|
| Go | sipcapture | github.com/sipcapture/homer-app |
< 0.0.0-20260625093330-5e90809657c9 Fix: upgrade to 0.0.0-20260625093330-5e90809657c9
|
Original advisory text
Homer: Complete Authentication Bypass When coordinator.jwt.secret Is Empty (Default)
Homer is open source telecom observability software. Prior to version 11.0.283, both JWT middleware functions (`JWTMiddleware` and `JWTMiddlewareV4`) immediately return `next(c)` when `jwtSecret == ""`. The JWT secret defaults to an empty string. On a default installation, all protected API endpoints under `/api/v1`, `/api/v3`, and `/api/v4` are completely unauthenticated. Version 11.0.283 patches the issue.
References
- https://github.com/sipcapture/homer/pull/839
- https://github.com/sipcapture/homer/commit/5e90809657c9df321db191a69c6050f873f56...
- https://github.com/sipcapture/homer/releases/tag/11.0.283
- https://github.com/advisories/GHSA-rqcc-94gv-wjm9
- https://github.com/sipcapture/homer/security/advisories/GHSA-rqcc-94gv-wjm9
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/62xxx/CVE-2026-62253... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-62253 Vendor Advisory
- https://github.com/sipcapture/homer Product
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Type
CWE-306Missing Authentication for Critical Function
Timeline
Published7 Oct 2026
Updated10 Oct 2026
First seen7 Oct 2026
Sources
CVE-2026-62253 · NVD
CVE-2026-62253 · MITRE
GHSA-rqcc-94gv-wjm9 · GHSA
CVE-2026-62253 · OSV
GHSA-rqcc-94gv-wjm9 · OSV
Track software like this
Free during beta