Skip to content
Threat Feed
critical advisory

Hardcoded Default Administrative Password in Homer

Fresh deployments of Homer use a hardcoded default password for the admin account, allowing unauthenticated remote attackers to gain full administrative access via CVE-2026-62252.

What's new

  • 1. added detection rule: Detects CVE-2026-62251 Exploitation - SQL Injection in /api/v4/statistics/query Oct 7, 16:59 via ghsa
  • 2. added detection rule: Detect Unauthenticated Access to Homer Admin API Oct 7, 16:57 via ghsa

Homer versions prior to 0.0.0-20260625091610-b2e942031ff8 contain a critical vulnerability (CVE-2026-62252) involving the use of hardcoded credentials. During the bootstrap process of a fresh deployment configured with internal authentication, the application automatically initializes an 'admin' account using a hardcoded SHA-256 hash that corresponds to the plaintext password 'sipcapture'.

The application lacks a first-login forced-password-change mechanism or any restrictive policy to prevent immediate unauthorized access. An attacker who can reach the login endpoint of a freshly deployed instance can perform a simple authentication request to obtain an administrative JSON Web Token (JWT). This vulnerability (CWE-798) grants the attacker full administrative control over the capture server, enabling them to manipulate packet capture settings, access sensitive session data, or further compromise the underlying host.

Attack Chain

  1. Attacker performs network reconnaissance to identify reachable Homer instances over the network.
  2. Attacker probes the endpoint '/api/v3/auth' to confirm the Homer instance is using internal authentication.
  3. Attacker sends a POST request to '/api/v3/auth' with the username 'admin' and password 'sipcapture'.
  4. The application validates the password against the hardcoded DefaultInternalAuthPasswordHash and returns an administrative JWT.
  5. Attacker utilizes the returned token in the 'Authorization' header of subsequent requests.
  6. Attacker calls '/api/v3/users' or other administrative APIs to manage users or access stored packet capture data.
  7. Attacker maintains administrative persistence by modifying system configurations or creating new administrative accounts.

Impact

Successful exploitation results in full administrative compromise of the Homer application. Attackers can view sensitive metadata and session traffic, export captured data, or modify system configurations. Any organization running a fresh instance of Homer that has not been patched or manually secured is at risk of immediate takeover.

Recommendation

Prioritized actions for security teams:

  • Immediately upgrade all Homer deployments to version 0.0.0-20260625091610-b2e942031ff8 or later to remediate CVE-2026-62252.
  • Scan perimeter-facing web infrastructure for HTTP traffic directed at /api/v3/auth, focusing on requests using the default 'admin' username.
  • Deploy the webserver-category Sigma rule below to detect and block unauthorized authentication attempts.
  • Audit existing Homer installations for administrative users created shortly after deployment to ensure password rotation has been enforced.

Immediate actions

Upgrade Homer to version 0.0.0-20260625091610-b2e942031ff8 or later.

IT Operations 24h

Threat Hunt

Identify all internet-exposed Homer instances.

T1078 high high confidence hunt now

Data: External network scan results

Mitigations

Patch to 0.0.0-20260625091610-b2e942031ff8.

immediate IT Operations

CVE-2026-62252

Detection coverage 3

Detect CVE-2026-62252 Exploitation - Authentication with Default Credentials

critical

Detects unauthorized attempts to authenticate to Homer using the default 'admin'/'sipcapture' credentials.

sigma tactics: initial_access techniques: T1078 sources: webserver

Detect Unauthenticated Access to Homer Admin API

critical

Detects unauthorized attempts to access protected Homer administrative endpoints (CVE-2026-62253)

sigma tactics: initial_access techniques: T1592 sources: webserver

Detects CVE-2026-62251 Exploitation - SQL Injection in /api/v4/statistics/query

high

Detects suspicious SQL injection attempts against the Homer statistics API by monitoring for common SQL keywords within the rawquery JSON payload.

sigma tactics: initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →