Authorization Flaw in HomeBox Affects User Inventory Management
CVE-2026-48826
8.1HIGH
What is CVE-2026-48826?
HomeBox is a home inventory and organization system that has a significant vulnerability prior to version 0.26.0. The issue resides in the HandleWipeInventory function, which incorrectly authorizes user actions based on a global owner value associated with self-registered users. This misconfiguration allows users to select an active group via the X-Tenant request header, thereby gaining the ability to permanently delete all associated inventory items. Such deletions are irreversible without external backups, posing a severe risk to data integrity and management. The vulnerability has been addressed in version 0.26.0.
Affected Version(s)
homebox < 0.26.0
