Group Membership Vulnerability in HomeBox by SysAdmins Media
CVE-2026-48974

5.4MEDIUM

Key Information:

Status
Vendor
CVE Published:
21 September 2026

What is CVE-2026-48974?

The HomeBox application, prior to version 0.26.0, has a security flaw that allows any authenticated user to add another account to their group without proper authorization. This is achieved through a problematic implementation of the HandleGroupMemberAdd and GroupService.AddMember functions, which do not enforce ownership, consent, or notification requirements. As a result, the targeted user’s email address and name can be revealed to unauthorized individuals via the group member list, potentially leading to further exploits such as cross-group inventory-wipe vulnerabilities. The issue has been addressed in version 0.26.0.

Affected Version(s)

homebox < 0.26.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.