CVE-2026-48975: HomeBox: Cross-Tenant IDOR in MaintenanceEntry Update and Delete Allows Tampering and Destruction of Any User's Maintenance History in Homebox

Published Sep 21, 2026
·
Updated

HomeBox is a home inventory and organization system. Prior to 0.26.0, MaintenanceEntryRepository.Update and MaintenanceEntryRepository.Delete in backend/internal/data/repo/repomaintenanceentry.go use UpdateOneID(id) and DeleteOneID(id) without verifying that the maintenance entry belongs to the authenticated user's active group. An authenticated low-privileged user who knows or enumerates another tenant's maintenance-entry UUID can overwrite that record or permanently delete it. This issue is fixed in version 0.26.0.

Affected Software

1 affected component
HomeBox<0.26.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade HomeBox to a version that resolves this vulnerability.

    Fixed in 0.26.0

Event History

Sep 21, 2026
CVE Published
via MITRE·05:42 PM
Data Sourced
via MITRE·05:42 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are affected?

HomeBox deployments running versions prior to 0.26.0 are affected. The issue is fixed in version 0.26.0.

2

What does an attacker need to exploit this issue?

An attacker needs an authenticated low-privileged HomeBox account and the UUID of a maintenance entry belonging to another tenant. The UUID may be known or enumerated.

3

Are maintenance records only exposed for viewing, or can they be changed?

An attacker can overwrite another tenant's maintenance entry or permanently delete it. The vulnerability affects update and delete operations.

4

What should teams do to remediate the issue?

Upgrade HomeBox to version 0.26.0, which fixes the missing active-group ownership verification for maintenance-entry updates and deletions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203