Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 21 Sep 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sysadminsmedia
Sysadminsmedia homebox |
|
| Vendors & Products |
Sysadminsmedia
Sysadminsmedia homebox |
Mon, 21 Sep 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HomeBox is a home inventory and organization system. Prior to 0.26.0, HandleWipeInventory in backend/app/api/handlers/v1/v1_ctrl_actions.go authorizes POST /v1/actions/wipe-inventory through the global ctx.User.IsOwner value instead of the caller's role in the active group, while the active group is selected through the X-Tenant request header. Because every self-registered user who creates a group receives the global owner value, a user who is also a member of another group can select that group with X-Tenant and permanently delete its complete inventory, which is not recoverable without external backups. This issue is fixed in version 0.26.0. | |
| Title | HomeBox: Cross-Group Inventory Wipe in Homebox via Global Owner Role and X-Tenant Header Switching | |
| Weaknesses | CWE-269 CWE-639 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-21T20:44:50.012Z
Reserved: 2026-05-22T20:57:10.977Z
Link: CVE-2026-48826
No data.
Status : Received
Published: 2026-09-21T18:17:08.073
Modified: 2026-09-21T18:17:08.073
Link: CVE-2026-48826
No data.
OpenCVE Enrichment
Updated: 2026-09-21T20:30:18Z