CVE-2026-48974
HomeBox: Forced Group Membership Without Consent in Homebox AddMember Handler
CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th
HomeBox is a home inventory and organization system. Prior to 0.26.0, POST /v1/groups/members invokes HandleGroupMemberAdd and GroupService.AddMember using a caller-supplied userID without requiring an owner role, an invitation token, target-user consent, or target-user notification. Any authenticated user can force another account into the caller's group, disclose the target user's email address and name through the resulting member list, and create the membership prerequisite used by a separate cross-group inventory-wipe vulnerability. This issue is fixed in version 0.26.0.
| CWE | CWE-841 CWE-862 |
| Vendor | sysadminsmedia |
| Product | homebox |
| Published | Sep 21, 2026 |
Stay Ahead of the Next One
Get instant alerts for sysadminsmedia homebox
Be the first to know when new medium vulnerabilities affecting sysadminsmedia homebox are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None
Affected Versions
sysadminsmedia / homebox
< 0.26.0