← Back to search

CVE-2026-49994

9.1 CRITICALpublic exploit available

Published 2026-09-28 · Updated 2026-09-28

AI risk analysis

Summary
The flaw in Bluehood allowed network attackers to read Bluetooth tracking data and modify application state without a session cookie, posing a significant security risk.
Exploitability
Exploitation is relatively easy for a network attacker with access to the dashboard port, requiring no session cookie.
Blast radius
If exploited, the attacker could modify critical application settings, potentially leading to data loss or misconfiguration.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to version 0.7.1 or later.
auth-bypasswebbluetoothconfig-modification

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Bluehood monitors local bluetooth activity. Prior to version 0.7.1, when auth_enabled is set in Bluehood, only the HTML page handlers enforced session validation. The /api/* handlers (settings, devices, groups, per-device endpoints including /api/device/{mac}/notes) called no auth check at all. A network attacker reachable on the dashboard port could read Bluetooth tracking data and modify application state — including the heartbeat URL, prune retention, device groups, and per-device notes — without a session cookie. This issue has been patched in version 0.7.1.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Weaknesses

CWE-306, CWE-862

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.