CVE-2026-62252: Homer: Hardcoded Default Admin Password 'sipcapture' With No Forced Change on First Login
Summary On every fresh Homer deployment using internal authentication, the bootstrap process automatically creates an admin account with the password sipcapture (stored as a legacy SHA-256 hex hash). There is no first-login forced-change mechanism. Any attacker who reaches the login endpoint immediately gains full administrative access.
Details config/config.go lines 858-861: go // DefaultInternalAuthPasswordHash is the SHA-256 hex digest of the default // bootstrap password (cleartext: sipcapture). const DefaultInternalAuthPasswordHash = "883ffc1f37fd0fe542b0fb9740035c4383e7d976c411161d24e62edace280f90"
coordinator/services/authbootstrap.go lines 20-71: EnsureBootstrapAdminUser() runs at startup. If no admin user exists, it inserts a row with username=admin, passwordhash=DefaultInternalAuthPasswordHash. No forcechange, no firstlogin flag, no expiry is set.
coordinator/services/authbootstraptest.go line 114 confirms the plaintext: go u, err := svc.Authenticate(ctx, "admin", "sipcapture")
passwordhash/password.go lines 36-45: Legacy SHA-256 hex hashes are accepted via legacySHA256HexEqual, so the default credential is functional on any deployment.
PoC bash Authenticate with default credentials — works on any fresh Homer deployment curl -s -X POST http://<homer-host>/api/v3/auth \ -H 'Content-Type: application/json' \ -d '{"username":"admin","password":"sipcapture"}' Response: {"token":"<admin-jwt>","data":{"userGroup":"admin"}}
Use the token to access all admin functionality curl -H "Authorization: Bearer <admin-jwt>" http://<homer-host>/api/v3/users
Impact Use of Hard-coded Credentials (CWE-798). Any attacker who can reach a freshly deployed Homer instance gains immediate full administrative access using the publicly documented default password, with no lockout, rate limiting, or forced password change required.
Fix Remove the hardcoded DefaultInternalAuthPasswordHash constant. Require operators to provide a hashed admin password in the configuration file. Alternatively, generate a random password on first startup, print it to stdout once, and immediately force a change on first login.
If possible, please apply for a CVE number when posting.
Other sources
Homer is open source telecom observability software. Prior to version 11.0.283, on every fresh Homer deployment using internal authentication, the bootstrap process automatically creates an admin account with the password sipcapture (stored as a legacy SHA-256 hex hash). There is no first-login forced-change mechanism. Any attacker who reaches the login endpoint immediately gains full administrative access. Version 11.0.283 patches the issue.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
go/github.com/sipcapture/homer-appto a version that resolves this vulnerability.Fixed in 0.0.0-20260625091610-b2e942031ff8 - Upgrade
Upgrade
Homerto a version that resolves this vulnerability.Fixed in 11.0.283 - Configuration
Require operators to provide a hashed admin password in the configuration file instead of using the hardcoded DefaultInternalAuthPasswordHash.
Homer internal authentication admin password = operator-provided hashed password
Event History
Frequently Asked Questions
Which deployments are exposed?
Fresh Homer deployments that use internal authentication are exposed when no admin user already exists. Startup creates the admin account automatically with the known bootstrap credential.
What does an attacker need to exploit this?
An attacker only needs network access to the login endpoint. No existing account, privileges, or user interaction is required.
How can I determine whether an instance has the vulnerable bootstrap account?
Check whether internal authentication is enabled and whether an admin user was created with the legacy SHA-256 hash 883ffc1f37fd0fe542b0fb9740035c4383e7d976c411161d24e62edace280f90. The affected bootstrap account uses the username admin.