HomeBox: Cross-Tenant IDOR in Notifier Update Leaks Shoutrrr Credentials and Allows Webhook Hijack
Published Sep 21, 2026
8.1
HIGHCVSS 3.1
EPSS 0.45%
Description
HomeBox is a home inventory and organization system. Prior to 0.26.0, NotifierRepository.Update in backend/internal/data/repo/repo_notifier.go updates a notifier through UpdateOneID(id) without requiring the record's user ID to match the authenticated user. An authenticated user who supplies another tenant's notifier UUID to PUT /v1/notifiers/{id} can read the returned stored url, which may contain plaintext Shoutrrr credentials for Slack, SMTP, Telegram, Pushover, or Discord, and can replace the URL to redirect the victim's notifications to an attacker-controlled webhook. This issue is fixed in version 0.26.0.
Affected products
-
Affected
- < 0.26.0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Sysadminsmedia | Homebox | unknown | Affected
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-84033 Advisory
- https://github.com/sysadminsmedia/homebox/commit/ed3216a80998dfd81d4418700696244144883160 x_refsource_MISC
- https://github.com/sysadminsmedia/homebox/releases/tag/v0.26.0 x_refsource_MISC
- https://github.com/sysadminsmedia/homebox/security/advisories/GHSA-mc8h-5c5v-37p7 x_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-84033 | Advisory | |
| https://github.com/sysadminsmedia/homebox/commit/ed3216a80998dfd81d4418700696244144883160 | x_refsource_MISC | |
| https://github.com/sysadminsmedia/homebox/releases/tag/v0.26.0 | x_refsource_MISC | |
| https://github.com/sysadminsmedia/homebox/security/advisories/GHSA-mc8h-5c5v-37p7 | x_refsource_CONFIRM |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data