Ghostwire

CVE-2026-48974: HomeBox is a home inventory and organization system. Prior to 0.26.0, POST /v1/groups/members invokes...

MEDIUM CVSS 0.0 EPSS 0.17%

Published: September 21, 2026 | Last Modified: September 21, 2026

Description

HomeBox is a home inventory and organization system. Prior to 0.26.0, POST /v1/groups/members invokes HandleGroupMemberAdd and GroupService.AddMember using a caller-supplied userID without requiring an owner role, an invitation token, target-user consent, or target-user notification. Any authenticated user can force another account into the caller's group, disclose the target user's email address and name through the resulting member list, and create the membership prerequisite used by a separate cross-group inventory-wipe vulnerability. This issue is fixed in version 0.26.0.

Ghostwire Analysis — What This Means Practically

Exploitation Probability (EPSS): Low — 0.17% (7th percentile)

Low exploitation probability based on current threat landscape data. Standard patching timeline is appropriate.

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (1 articles)

References