CVE-2026-62253 PUBLISHED

Homer: Complete Authentication Bypass When coordinator.jwt.secret Is Empty (Default)

Assigner: GitHub_M
Reserved: 13.07.2026 Published: 07.10.2026 Updated: 07.10.2026

Homer is open source telecom observability software. Prior to version 11.0.283, both JWT middleware functions (JWTMiddleware and JWTMiddlewareV4) immediately return next(c) when jwtSecret == "". The JWT secret defaults to an empty string. On a default installation, all protected API endpoints under /api/v1, /api/v3, and /api/v4 are completely unauthenticated. Version 11.0.283 patches the issue.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8

Product Status

Vendor sipcapture
Product homer
Versions
  • Version < 11.0.283 is affected

References

Problem Types

  • CWE-306: Missing Authentication for Critical Function CWE