CVE-2026-62253: Homer: Complete Authentication Bypass When coordinator.jwt.secret Is Empty (Default)

Published Oct 7, 2026
·
Updated

Summary Both JWT middleware functions (JWTMiddleware and JWTMiddlewareV4) immediately return next(c) when jwtSecret == "". The JWT secret defaults to an empty string. On a default installation, all protected API endpoints under /api/v1, /api/v3, and /api/v4 are completely unauthenticated.

Details coordinator/handlers/auth.go lines 298-304: go func (h Auth) JWTMiddleware() echo.MiddlewareFunc { return func(next echo.HandlerFunc) echo.HandlerFunc { return func(c echo.Context) error { if h.jwtSecret == "" { return next(c) // bypass — no validation performed }

coordinator/handlers/authv4helpers.go lines 177-182: go func (h Auth) JWTMiddlewareV4() echo.MiddlewareFunc { return func(next echo.HandlerFunc) echo.HandlerFunc { return func(c echo.Context) error { if h.jwtSecret == "" { return next(c) // same bypass

coordinator/coordinator.go lines 315-317: go if c.config.JWT.Secret != "" { protected.Use(authHandler.JWTMiddleware()) // middleware not even registered when secret is empty }

config/config.go line 845: Secret field struct tag has default:"". The example config ships a placeholder value, but the Go struct default (used when no config is provided) is empty.

PoC bash On a default Homer installation (no JWT secret configured), all protected routes are open: curl http://<homer-host>/api/v3/users Returns full user list with no credentials

curl http://<homer-host>/api/v3/databases Returns all database connection strings

curl -X POST http://<homer-host>/api/v3/users \ -H 'Content-Type: application/json' \ -d '{"username":"attacker","password":"pw","partid":10,"usergroup":"admin"}' Creates a new admin user with no credentials

Impact Missing Authentication for Critical Function (CWE-306). On a default Homer installation with no JWT secret configured, every admin API endpoint is completely unauthenticated. Attackers can read/write all configuration, users, database connections, and stored VoIP call data.

Fix Fail closed: if JWT.Secret is empty at startup, abort with a fatal error requiring the operator to set a strong secret. Remove the empty-string shortcircuit from both middleware functions: go if h.jwtSecret == "" { log.Fatal("coordinator.jwt.secret must be set to a non-empty value") }

If possible, please apply for a CVE number when posting.

Other sources

Homer is open source telecom observability software. Prior to version 11.0.283, both JWT middleware functions (JWTMiddleware and JWTMiddlewareV4) immediately return next(c) when jwtSecret == "". The JWT secret defaults to an empty string. On a default installation, all protected API endpoints under /api/v1, /api/v3, and /api/v4 are completely unauthenticated. Version 11.0.283 patches the issue.

— MITRE

Affected Software

1 affected componentFixes available
go/github.com/sipcapture/homer-app<0.0.0-20260625093330-5e90809657c9
0.0.0-20260625093330-5e90809657c9

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade go/github.com/sipcapture/homer-app to a version that resolves this vulnerability.

    Fixed in 0.0.0-20260625093330-5e90809657c9
  2. Upgrade

    Upgrade Homer to a version that resolves this vulnerability.

    Fixed in 11.0.283
  3. Configuration

    Set coordinator.jwt.secret to a non-empty strong secret; startup must fail if JWT.Secret is empty.

    Homer coordinator coordinator.jwt.secret = non-empty strong secret

Event History

Oct 7, 2026
CVE Published
via MITRE·04:11 PM
Data Sourced
via MITRE·04:11 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·04:11 PM
Data Sourced
via GitHub·04:11 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which deployments are exposed?

Deployments using the default empty JWT secret are exposed. Protected API routes under /api/v1, /api/v3, and /api/v4 are unauthenticated in that configuration.

2

What does an attacker need to exploit this issue?

An attacker only needs network access to the affected API endpoints. No JWT, credentials, privileges, or user interaction are required when the JWT secret is empty.

3

What can be done if an update cannot be applied immediately?

Configure a non-empty JWT secret. The coordinator registers JWT middleware only when the configured JWT secret is not empty.

4

How can I determine whether my instance is affected?

Check the configured JWT Secret value rather than relying on the example configuration placeholder. An empty value means the JWT middleware bypasses validation and protected API endpoints are exposed.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203