Homarr is an open-source dashboard. Prior to version 1.54.0, the integration.all tRPC endpoint in Homarr is exposed as a publicProcedure, allowing unauthenticated users to retrieve a complete list of configured integrations. This metadata includes sensitive information such as internal service URLs, integration names, and service types. This issue has been patched in version 1.54.0.
Metrics
Affected Vendors & Products
References
History
Sat, 07 Mar 2026 06:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Homarr is an open-source dashboard. Prior to version 1.54.0, the integration.all tRPC endpoint in Homarr is exposed as a publicProcedure, allowing unauthenticated users to retrieve a complete list of configured integrations. This metadata includes sensitive information such as internal service URLs, integration names, and service types. This issue has been patched in version 1.54.0. | |
| Title | Homarr: Unauthenticated Information Disclosure (Integration Metadata Leak) | |
| Weaknesses | CWE-200 CWE-862 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-07T05:54:48.829Z
Reserved: 2026-02-24T02:31:33.265Z
Link: CVE-2026-27796
No data.
Status : Received
Published: 2026-03-07T06:16:09.663
Modified: 2026-03-07T06:16:09.663
Link: CVE-2026-27796
No data.
OpenCVE Enrichment
No data.