Back to database
Schedule54Critical9.8VulnerabilityCVE-2026-62252No patch link observed

CVE-2026-62252 — Homer is open source telecom observability software.

Published Oct 7, 2026, 05:16 PM UTCIngested 1d agoSource NVD(cve-db)CVE-2026-62252

Description

Homer is open source telecom observability software. Prior to version 11.0.283, on every fresh Homer deployment using internal authentication, the bootstrap process automatically creates an `admin` account with the password `sipcapture` (stored as a legacy SHA-256 hex hash). There is no first-login forced-change mechanism. Any attacker who reaches the login endpoint immediately gains full administrative access. Version 11.0.283 patches the issue.

CVSS v3.1 base metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.8

Critical severity

Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.

AV

Network

Attack Vector

AC

Low

Attack Complexity

PR

None

Privileges Required

UI

None

User Interaction

S

Unchanged

Scope

C

High

Confidentiality

I

High

Integrity

A

High

Availability

Affected

Vendor
Go
Product
github.com/sipcapture/homer-app

Versions

  • pkg:golang/github.com/sipcapture/homer-app < 0.0.0-20260625091610-b2e942031ff8

Stated as the source expressed them.