CVE-2026-55844: Home Assistant: iOS Companion App ignores internal SSID allowlist for connections – possible leak of access token and sensor data

Published Jun 29, 2026
·
Updated

Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2025.5.0, The iOS companion app ignores the SSID allowlist for internal networks. The app uses SSID to detect when to use the internal URL, but whenever the app cannot find any other URL to be used, it fallbacks to the internal URL as well, which can expose user's token when connected to a not secure network. This vulnerability is fixed in 2025.5.0.

Affected Software

1 affected component
Home Assistant iOS Companion App<2025.5.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Home Assistant iOS Companion App to a version that resolves this vulnerability.

    Fixed in 2025.5.0

Event History

Jun 29, 2026
CVE Published
via MITRE·02:19 PM
Data Sourced
via MITRE·02:19 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-55844?

CVE-2026-55844 has a severity rating of high with a score of 7.5.

2

What does CVE-2026-55844 affect?

CVE-2026-55844 affects the Home Assistant iOS Companion App by allowing it to ignore the SSID allowlist for internal network connections.

3

How can I mitigate CVE-2026-55844?

To mitigate CVE-2026-55844, update the iOS Companion App to version 2025.5.0 or later where the issue has been resolved.

4

What data could be exposed due to CVE-2026-55844?

CVE-2026-55844 could potentially leak access tokens and sensor data due to the app's improper handling of internal network SSIDs.

5

Is CVE-2026-55844 applicable to all versions of the Home Assistant iOS Companion App?

CVE-2026-55844 is applicable to versions prior to 2025.5.0 of the Home Assistant iOS Companion App.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203