Group Membership Vulnerability in HomeBox by SysAdmins Media
CVE-2026-48974
5.4MEDIUM
What is CVE-2026-48974?
The HomeBox application, prior to version 0.26.0, has a security flaw that allows any authenticated user to add another account to their group without proper authorization. This is achieved through a problematic implementation of the HandleGroupMemberAdd and GroupService.AddMember functions, which do not enforce ownership, consent, or notification requirements. As a result, the targeted user’s email address and name can be revealed to unauthorized individuals via the group member list, potentially leading to further exploits such as cross-group inventory-wipe vulnerabilities. The issue has been addressed in version 0.26.0.
Affected Version(s)
homebox < 0.26.0
