CVE-2026-48976: Sysadminsmedia Homebox
High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.
HomeBox is a home inventory and organization system. Prior to 0.26.0, NotifierRepository.Update in backend/internal/data/repo/repo_notifier.go updates a notifier through UpdateOneID(id) without requiring the record's user ID to match the authenticated user. An authenticated user who supplies another tenant's notifier UUID to PUT /v1/notifiers/{id} can read the returned stored url, which may contain plaintext Shoutrrr credentials for Slack, SMTP, Telegram, Pushover, or Discord, and can replace the URL to redirect the victim's notifications to an attacker-controlled webhook. This issue is fixed in version 0.26.0.
Affected products
- Sysadminsmedia Homebox: before 0.26.0 (fixed in 0.26.0)
Published 2026-09-21. Last modified 2026-09-23.