{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-62252/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:sipcapture:homer-app:*:*:*:*:*:*:*:*"],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["homer-app (\u003c 0.0.0-20260625091610-b2e942031ff8)","homer-app (\u003c 0.0.0-20260625093330-5e90809657c9)","homer-app (\u003c 0.0.0-20260625085520-a7d027dc684b)"],"_cs_severities":["critical"],"_cs_tags":["cve-2026-62252","authentication","web-application","authentication-bypass","cve-2026-62253","sipcapture","sqli","vulnerability"],"_cs_type":"advisory","_cs_vendors":["sipcapture"],"content_html":"\u003cp\u003eHomer versions prior to 0.0.0-20260625091610-b2e942031ff8 contain a critical vulnerability (CVE-2026-62252) involving the use of hardcoded credentials. During the bootstrap process of a fresh deployment configured with internal authentication, the application automatically initializes an 'admin' account using a hardcoded SHA-256 hash that corresponds to the plaintext password 'sipcapture'.\u003c/p\u003e\n\u003cp\u003eThe application lacks a first-login forced-password-change mechanism or any restrictive policy to prevent immediate unauthorized access. An attacker who can reach the login endpoint of a freshly deployed instance can perform a simple authentication request to obtain an administrative JSON Web Token (JWT). This vulnerability (CWE-798) grants the attacker full administrative control over the capture server, enabling them to manipulate packet capture settings, access sensitive session data, or further compromise the underlying host.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs network reconnaissance to identify reachable Homer instances over the network.\u003c/li\u003e\n\u003cli\u003eAttacker probes the endpoint '/api/v3/auth' to confirm the Homer instance is using internal authentication.\u003c/li\u003e\n\u003cli\u003eAttacker sends a POST request to '/api/v3/auth' with the username 'admin' and password 'sipcapture'.\u003c/li\u003e\n\u003cli\u003eThe application validates the password against the hardcoded \u003ccode\u003eDefaultInternalAuthPasswordHash\u003c/code\u003e and returns an administrative JWT.\u003c/li\u003e\n\u003cli\u003eAttacker utilizes the returned token in the 'Authorization' header of subsequent requests.\u003c/li\u003e\n\u003cli\u003eAttacker calls '/api/v3/users' or other administrative APIs to manage users or access stored packet capture data.\u003c/li\u003e\n\u003cli\u003eAttacker maintains administrative persistence by modifying system configurations or creating new administrative accounts.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full administrative compromise of the Homer application. Attackers can view sensitive metadata and session traffic, export captured data, or modify system configurations. Any organization running a fresh instance of Homer that has not been patched or manually secured is at risk of immediate takeover.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately upgrade all Homer deployments to version 0.0.0-20260625091610-b2e942031ff8 or later to remediate CVE-2026-62252.\u003c/li\u003e\n\u003cli\u003eScan perimeter-facing web infrastructure for HTTP traffic directed at /api/v3/auth, focusing on requests using the default 'admin' username.\u003c/li\u003e\n\u003cli\u003eDeploy the webserver-category Sigma rule below to detect and block unauthorized authentication attempts.\u003c/li\u003e\n\u003cli\u003eAudit existing Homer installations for administrative users created shortly after deployment to ensure password rotation has been enforced.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-07T16:59:46Z","date_published":"2026-10-07T16:57:01Z","id":"https://feed.craftedsignal.io/briefs/2026-10-homer-hardcoded-credentials/","summary":"Fresh deployments of Homer use a hardcoded default password for the admin account, allowing unauthenticated remote attackers to gain full administrative access via CVE-2026-62252.","title":"Hardcoded Default Administrative Password in Homer","url":"https://feed.craftedsignal.io/briefs/2026-10-homer-hardcoded-credentials/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-62252","version":"https://jsonfeed.org/version/1.1"}