CVE-2026-62252 — Homer is open source telecom observability software.
Description
Homer is open source telecom observability software. Prior to version 11.0.283, on every fresh Homer deployment using internal authentication, the bootstrap process automatically creates an `admin` account with the password `sipcapture` (stored as a legacy SHA-256 hex hash). There is no first-login forced-change mechanism. Any attacker who reaches the login endpoint immediately gains full administrative access. Version 11.0.283 patches the issue.
CVSS v3.1 base metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCritical severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
Low
Attack Complexity
PR
None
Privileges Required
UI
None
User Interaction
S
Unchanged
Scope
C
High
Confidentiality
I
High
Integrity
A
High
Availability
Affected
- Vendor
- Go
- Product
- github.com/sipcapture/homer-app
Versions
- pkg:golang/github.com/sipcapture/homer-app < 0.0.0-20260625091610-b2e942031ff8
Stated as the source expressed them.
References
- otherOSV webhttps://github.com/sipcapture/homer/commit/b2e942031ff8cd7435a244ebef306ee97d16b809
- otherOSV webhttps://github.com/sipcapture/homer/pull/838
- otherOSV webhttps://github.com/sipcapture/homer/releases/tag/11.0.283
- otherOSV webhttps://github.com/sipcapture/homer/security/advisories/GHSA-6xp5-7rcx-xfgx
- advisoryOSV GHSA-6xp5-7rcx-xfgxhttps://osv.dev/vulnerability/GHSA-6xp5-7rcx-xfgx
- vendorOSV packagehttps://github.com/sipcapture/homer
Related threats
same CWE or vendorCVE-2026-84250 — IBM Guardium Data Protection 12.2 is vulnerable due to weak cryptographic protection and a hard-coded recovery key in the pkcrypto passkey component.
CVE-2026-84250 · 2h ago
CVE-2026-107386 — amqp091-go is a Go AMQP 0.9.1 client.
CVE-2026-107386 · 3h ago
Coraza: Resource exhaustion via deferred file handle accumulation in multipart body processor
OSV · 5h ago
Coraza: URL-encoded form Content-Type parameters bypass Coraza body inspection
OSV · 5h ago
Coraza: Unbounded recursion in JSON response body processor causes CPU exhaustion
OSV · 5h ago
Coraza: Multipart filename* (RFC 5987) charset restriction lets a decoy filename bypass FILES-based rules
OSV · 5h ago