๐Ÿ” CVE Alert

CVE-2026-48976

HIGH 8.1

HomeBox: Cross-Tenant IDOR in Notifier Update Leaks Shoutrrr Credentials and Allows Webhook Hijack

CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
0th

HomeBox is a home inventory and organization system. Prior to 0.26.0, NotifierRepository.Update in backend/internal/data/repo/repo_notifier.go updates a notifier through UpdateOneID(id) without requiring the record's user ID to match the authenticated user. An authenticated user who supplies another tenant's notifier UUID to PUT /v1/notifiers/{id} can read the returned stored url, which may contain plaintext Shoutrrr credentials for Slack, SMTP, Telegram, Pushover, or Discord, and can replace the URL to redirect the victim's notifications to an attacker-controlled webhook. This issue is fixed in version 0.26.0.

CWE CWE-522 CWE-639
Vendor sysadminsmedia
Product homebox
Published Sep 21, 2026
Last Updated Sep 21, 2026
Stay Ahead of the Next One

Get instant alerts for sysadminsmedia homebox

Be the first to know when new high vulnerabilities affecting sysadminsmedia homebox are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

sysadminsmedia / homebox
< 0.26.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/sysadminsmedia/homebox/security/advisories/GHSA-mc8h-5c5v-37p7 github.com: https://github.com/sysadminsmedia/homebox/commit/ed3216a80998dfd81d4418700696244144883160 github.com: https://github.com/sysadminsmedia/homebox/releases/tag/v0.26.0