CVE-2026-62252: Homer: Hardcoded Default Admin Password 'sipcapture' With No Forced Change on First Login

Published Oct 7, 2026
·
Updated

Summary On every fresh Homer deployment using internal authentication, the bootstrap process automatically creates an admin account with the password sipcapture (stored as a legacy SHA-256 hex hash). There is no first-login forced-change mechanism. Any attacker who reaches the login endpoint immediately gains full administrative access.

Details config/config.go lines 858-861: go // DefaultInternalAuthPasswordHash is the SHA-256 hex digest of the default // bootstrap password (cleartext: sipcapture). const DefaultInternalAuthPasswordHash = "883ffc1f37fd0fe542b0fb9740035c4383e7d976c411161d24e62edace280f90"

coordinator/services/authbootstrap.go lines 20-71: EnsureBootstrapAdminUser() runs at startup. If no admin user exists, it inserts a row with username=admin, passwordhash=DefaultInternalAuthPasswordHash. No forcechange, no firstlogin flag, no expiry is set.

coordinator/services/authbootstraptest.go line 114 confirms the plaintext: go u, err := svc.Authenticate(ctx, "admin", "sipcapture")

passwordhash/password.go lines 36-45: Legacy SHA-256 hex hashes are accepted via legacySHA256HexEqual, so the default credential is functional on any deployment.

PoC bash Authenticate with default credentials — works on any fresh Homer deployment curl -s -X POST http://<homer-host>/api/v3/auth \ -H 'Content-Type: application/json' \ -d '{"username":"admin","password":"sipcapture"}' Response: {"token":"<admin-jwt>","data":{"userGroup":"admin"}}

Use the token to access all admin functionality curl -H "Authorization: Bearer <admin-jwt>" http://<homer-host>/api/v3/users

Impact Use of Hard-coded Credentials (CWE-798). Any attacker who can reach a freshly deployed Homer instance gains immediate full administrative access using the publicly documented default password, with no lockout, rate limiting, or forced password change required.

Fix Remove the hardcoded DefaultInternalAuthPasswordHash constant. Require operators to provide a hashed admin password in the configuration file. Alternatively, generate a random password on first startup, print it to stdout once, and immediately force a change on first login.

If possible, please apply for a CVE number when posting.

Other sources

Homer is open source telecom observability software. Prior to version 11.0.283, on every fresh Homer deployment using internal authentication, the bootstrap process automatically creates an admin account with the password sipcapture (stored as a legacy SHA-256 hex hash). There is no first-login forced-change mechanism. Any attacker who reaches the login endpoint immediately gains full administrative access. Version 11.0.283 patches the issue.

— MITRE

Affected Software

1 affected componentFixes available
go/github.com/sipcapture/homer-app<0.0.0-20260625091610-b2e942031ff8
0.0.0-20260625091610-b2e942031ff8

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade go/github.com/sipcapture/homer-app to a version that resolves this vulnerability.

    Fixed in 0.0.0-20260625091610-b2e942031ff8
  2. Upgrade

    Upgrade Homer to a version that resolves this vulnerability.

    Fixed in 11.0.283
  3. Configuration

    Require operators to provide a hashed admin password in the configuration file instead of using the hardcoded DefaultInternalAuthPasswordHash.

    Homer internal authentication admin password = operator-provided hashed password

Event History

Oct 7, 2026
Advisory Published
via GitHub·04:12 PM
Data Sourced
via GitHub·04:12 PM
DescriptionSeverityWeaknessAffected Software
CVE Published
via MITRE·04:12 PM
Data Sourced
via MITRE·04:12 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed?

Fresh Homer deployments that use internal authentication are exposed when no admin user already exists. Startup creates the admin account automatically with the known bootstrap credential.

2

What does an attacker need to exploit this?

An attacker only needs network access to the login endpoint. No existing account, privileges, or user interaction is required.

3

How can I determine whether an instance has the vulnerable bootstrap account?

Check whether internal authentication is enabled and whether an admin user was created with the legacy SHA-256 hash 883ffc1f37fd0fe542b0fb9740035c4383e7d976c411161d24e62edace280f90. The affected bootstrap account uses the username admin.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203