Ghostwire

CVE-2026-48826: HomeBox is a home inventory and organization system. Prior to 0.26.0, HandleWipeInventory in...

HIGH CVSS 0.0 EPSS 0.26%

Published: September 21, 2026 | Last Modified: September 21, 2026

Description

HomeBox is a home inventory and organization system. Prior to 0.26.0, HandleWipeInventory in backend/app/api/handlers/v1/v1_ctrl_actions.go authorizes POST /v1/actions/wipe-inventory through the global ctx.User.IsOwner value instead of the caller's role in the active group, while the active group is selected through the X-Tenant request header. Because every self-registered user who creates a group receives the global owner value, a user who is also a member of another group can select that group with X-Tenant and permanently delete its complete inventory, which is not recoverable without external backups. This issue is fixed in version 0.26.0.

Ghostwire Analysis — What This Means Practically

Exploitation Probability (EPSS): Low — 0.26% (19th percentile)

Low exploitation probability based on current threat landscape data. Standard patching timeline is appropriate.

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (1 articles)

References