CVE-2026-48974
5.4 MEDIUMpublic exploit availablePublished 2026-09-21 · Updated 2026-09-21
AI risk analysis
- Summary
- The flaw allows any authenticated user to add another account to their group without proper authorization, leading to potential unauthorized access and data exposure.
- Exploitability
- Exploitation is relatively easy as it requires only an authenticated session with minimal interaction from the target user.
- Blast radius
- If exploited, this could lead to significant privacy breaches and control over shared resources within the HomeBox system.
- Prioritized remediation
- Upgrade to version 0.26.0 or later to apply the necessary security fixes.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
HomeBox is a home inventory and organization system. Prior to 0.26.0, POST /v1/groups/members invokes HandleGroupMemberAdd and GroupService.AddMember using a caller-supplied userID without requiring an owner role, an invitation token, target-user consent, or target-user notification. Any authenticated user can force another account into the caller's group, disclose the target user's email address and name through the resulting member list, and create the membership prerequisite used by a separate cross-group inventory-wipe vulnerability. This issue is fixed in version 0.26.0.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Weaknesses
CWE-841, CWE-862
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- CRITICALCVE-2026-15958
- HIGHCVE-2026-6079
- MEDIUMCVE-2026-61748PoC
- HIGHCVE-2026-63330PoC
- HIGHCVE-2026-7520
- MEDIUMCVE-2026-77520PoC
- MEDIUMCVE-2026-7753
- HIGHCVE-2026-55739PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.