Back

HIGH

HomeBox: Cross-Tenant IDOR in Notifier Update Leaks Shoutrrr Credentials and Allows Webhook Hijack

Published Sep 21, 2026

Description

HomeBox is a home inventory and organization system. Prior to 0.26.0, NotifierRepository.Update in backend/internal/data/repo/repo_notifier.go updates a notifier through UpdateOneID(id) without requiring the record's user ID to match the authenticated user. An authenticated user who supplies another tenant's notifier UUID to PUT /v1/notifiers/{id} can read the returned stored url, which may contain plaintext Shoutrrr credentials for Slack, SMTP, Telegram, Pushover, or Discord, and can replace the URL to redirect the victim's notifications to an attacker-controlled webhook. This issue is fixed in version 0.26.0.

Affected products

Remediation

No remediation recorded yet.

References (4)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner GitHub_M
Published Sep 21, 2026
Updated Sep 21, 2026
Reserved May 26, 2026

CISA Vulnrichment

Updated Sep 21, 2026

NVD

Status Received
Modified Sep 21, 2026

Red Hat

No data

ENISA EUVD

Assigner GitHub_M
Published Sep 21, 2026
Updated Sep 21, 2026

GitHub

No data