CVE-2026-62252 PUBLISHED

Homer: Hardcoded Default Admin Password 'sipcapture' With No Forced Change on First Login

Assigner: GitHub_M
Reserved: 13.07.2026 Published: 07.10.2026 Updated: 07.10.2026

Homer is open source telecom observability software. Prior to version 11.0.283, on every fresh Homer deployment using internal authentication, the bootstrap process automatically creates an admin account with the password sipcapture (stored as a legacy SHA-256 hex hash). There is no first-login forced-change mechanism. Any attacker who reaches the login endpoint immediately gains full administrative access. Version 11.0.283 patches the issue.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8

Product Status

Vendor sipcapture
Product homer
Versions
  • Version < 11.0.283 is affected

References

Problem Types

  • CWE-798: Use of Hard-coded Credentials CWE