Hardcoded Default Administrative Password in Homer
Fresh deployments of Homer use a hardcoded default password for the admin account, allowing unauthenticated remote attackers to gain full administrative access via CVE-2026-62252.
What's new
Homer versions prior to 0.0.0-20260625091610-b2e942031ff8 contain a critical vulnerability (CVE-2026-62252) involving the use of hardcoded credentials. During the bootstrap process of a fresh deployment configured with internal authentication, the application automatically initializes an 'admin' account using a hardcoded SHA-256 hash that corresponds to the plaintext password 'sipcapture'.
The application lacks a first-login forced-password-change mechanism or any restrictive policy to prevent immediate unauthorized access. An attacker who can reach the login endpoint of a freshly deployed instance can perform a simple authentication request to obtain an administrative JSON Web Token (JWT). This vulnerability (CWE-798) grants the attacker full administrative control over the capture server, enabling them to manipulate packet capture settings, access sensitive session data, or further compromise the underlying host.
Attack Chain
- Attacker performs network reconnaissance to identify reachable Homer instances over the network.
- Attacker probes the endpoint '/api/v3/auth' to confirm the Homer instance is using internal authentication.
- Attacker sends a POST request to '/api/v3/auth' with the username 'admin' and password 'sipcapture'.
- The application validates the password against the hardcoded
DefaultInternalAuthPasswordHashand returns an administrative JWT. - Attacker utilizes the returned token in the 'Authorization' header of subsequent requests.
- Attacker calls '/api/v3/users' or other administrative APIs to manage users or access stored packet capture data.
- Attacker maintains administrative persistence by modifying system configurations or creating new administrative accounts.
Impact
Successful exploitation results in full administrative compromise of the Homer application. Attackers can view sensitive metadata and session traffic, export captured data, or modify system configurations. Any organization running a fresh instance of Homer that has not been patched or manually secured is at risk of immediate takeover.
Recommendation
Prioritized actions for security teams:
- Immediately upgrade all Homer deployments to version 0.0.0-20260625091610-b2e942031ff8 or later to remediate CVE-2026-62252.
- Scan perimeter-facing web infrastructure for HTTP traffic directed at /api/v3/auth, focusing on requests using the default 'admin' username.
- Deploy the webserver-category Sigma rule below to detect and block unauthorized authentication attempts.
- Audit existing Homer installations for administrative users created shortly after deployment to ensure password rotation has been enforced.
Immediate actions
Upgrade Homer to version 0.0.0-20260625091610-b2e942031ff8 or later.
Threat Hunt
Identify all internet-exposed Homer instances.
Data: External network scan results
Mitigations
Patch to 0.0.0-20260625091610-b2e942031ff8.
CVE-2026-62252
Detection coverage 3
Detect CVE-2026-62252 Exploitation - Authentication with Default Credentials
criticalDetects unauthorized attempts to authenticate to Homer using the default 'admin'/'sipcapture' credentials.
Detect Unauthenticated Access to Homer Admin API
criticalDetects unauthorized attempts to access protected Homer administrative endpoints (CVE-2026-62253)
Detects CVE-2026-62251 Exploitation - SQL Injection in /api/v4/statistics/query
highDetects suspicious SQL injection attempts against the Homer statistics API by monitoring for common SQL keywords within the rawquery JSON payload.
Detection queries are available on the platform. Get full rules →