Local Control and Privacy Vulnerability in Home Assistant Companion App
CVE-2026-66060

7.1HIGH

Key Information:

Status
Vendor
CVE Published:
7 August 2026

What is CVE-2026-66060?

The Home Assistant Companion app has a serious vulnerability that treats NFC or QR tag links delivered through an OS-level routing mechanism as though they were physically scanned. This flaw, present in versions prior to 2026.5.3, does not validate the calling application or require user interaction, allowing any untrusted app on the device to trigger automation processes. Consequently, this permits unauthorized third-party applications to execute actions within Home Assistant without proper authentication. The issue has been addressed and resolved in version 2026.8.1, enhancing the app's security against such unauthorized automation.

Affected Version(s)

core < 2026.5.3

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.