๐Ÿ” CVE Alert

CVE-2026-49994

CRITICAL 9.1

Bluehood: Missing authentication on Bluehood API routes when web auth is enabled

CVSS Score
9.1
EPSS Score
0.0%
EPSS Percentile
0th

Bluehood monitors local bluetooth activity. Prior to version 0.7.1, when auth_enabled is set in Bluehood, only the HTML page handlers enforced session validation. The /api/* handlers (settings, devices, groups, per-device endpoints including /api/device/{mac}/notes) called no auth check at all. A network attacker reachable on the dashboard port could read Bluetooth tracking data and modify application state โ€” including the heartbeat URL, prune retention, device groups, and per-device notes โ€” without a session cookie. This issue has been patched in version 0.7.1.

CWE CWE-306 CWE-862
Vendor dannymcc
Product bluehood
Published Sep 28, 2026
Last Updated Sep 28, 2026
Stay Ahead of the Next One

Get instant alerts for dannymcc bluehood

Be the first to know when new critical vulnerabilities affecting dannymcc bluehood are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

dannymcc / bluehood
< 0.7.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/dannymcc/bluehood/security/advisories/GHSA-qj2j-wcg3-74jw github.com: https://github.com/dannymcc/bluehood/commit/401479938c0deb1f6f6847d442f98a2d03efca68 github.com: https://github.com/dannymcc/bluehood/releases/tag/v0.7.1