CVE-2026-34205: Home Assistant: Unauthenticated App (Add-on) Endpoints Exposed to Local Network via Host Network Mode

Published Mar 27, 2026
·
Updated

Home Assistant is open source home automation software that puts local control and privacy first. Home Assistant apps (formerly add-ons) configured with host network mode expose unauthenticated endpoints bound to the internal Docker bridge interface to the local network. On Linux, this configuration does not restrict access to the app as intended, allowing any device on the same network to reach these endpoints without authentication. Home Assistant Supervisor 2026.03.02 addresses the issue.

Affected Software

1 affected component
Home Assistant Home Assistant Supervisor<2026.03.02

Event History

Mar 27, 2026
CVE Published
via MITRE·07:41 PM
Data Sourced
via MITRE·07:41 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-34205?

CVE-2026-34205 is classified as a moderate severity vulnerability.

2

How do I fix CVE-2026-34205?

To fix CVE-2026-34205, reconfigure affected Home Assistant apps to not use host network mode.

3

Who is affected by CVE-2026-34205?

CVE-2026-34205 affects installations of Home Assistant Supervisor version prior to 2026.03.02.

4

What is the impact of CVE-2026-34205?

The impact of CVE-2026-34205 allows unauthenticated access to certain endpoints on the local network.

5

Is there a workaround for CVE-2026-34205?

A temporary workaround for CVE-2026-34205 is to disable or limit access to host network mode for critical apps.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203