SQL Injection Vulnerability in Homer Telecom Observability Software by Sipcapture
CVE-2026-62251

8.1HIGH

Key Information:

Vendor

Sipcapture

Status
Vendor
CVE Published:
7 October 2026

What is CVE-2026-62251?

Homer, an open-source telecom observability tool, faces a critical SQL injection vulnerability through its V4StatisticsQuery handler. This flaw enables authenticated users to send arbitrary SQL queries to the DuckDB database without proper validation, potentially exposing sensitive data. The issue resides in the way user-supplied input is handled; specifically, the handler does not invoke the necessary sqlvalidator.ValidateRawSQL function that is employed throughout the rest of the application. It is imperative for users to upgrade to version 11.0.283 or later to mitigate this vulnerability and ensure the security of their systems.

Affected Version(s)

homer < 11.0.283

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.