CVE-2026-62253: critical vulnerability in sipcapture homer
Homer: Complete Authentication Bypass When coordinator.jwt.secret Is Empty (Default)
Published
25Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 9.8
exploitation probability
—
observed exploitation
nono source reports it
Homer is open source telecom observability software. Prior to version 11.0.283, both JWT middleware functions (`JWTMiddleware` and `JWTMiddlewareV4`) immediately return `next(c)` when `jwtSecret == ""`. The JWT secret defaults to an empty string. On a default installation, all protected API endpoints under `/api/v1`, `/api/v3`, and `/api/v4` are completely unauthenticated. Version 11.0.283 patches the issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
sipcapture · homerRelated CVEs — sipcapture homer
In the same product, most dangerous first.