← Zurück zur CVE-Suche

CVE-2026-40196

HomeBox

Beschreibung

HomeBox is a home inventory and organization system. Versions prior to 0.25.0 contain a vulnerability where the defaultGroup ID remained permanently assigned to a user after being invited to a group, even after their access to that group was revoked. While the web interface correctly enforced the access revocation and prevented the user from viewing or modifying the group-s contents, the API did not. Because the original group ID persisted as the user-s defaultGroup, and this value was not properly validated when the X-Tenant header was omitted, the user could still perform full CRUD operations on the group-s collections through the API, bypassing the intended access controls. This issue has been fixed in version 0.25.0.

CVSS 8.1EPSS 0.247%Risiko 0.83
Quelle öffnen
Veröffentlicht
2026-04-17 21:16:33
Betroffene Versionen
<0.25.0
Typ
Installed app
Vektor
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N