s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

CVE-2026-48826

📛 CVE Title

HomeBox: Cross-Group Inventory Wipe in Homebox via Global Owner Role and X-Tenant Header Switching

Description

HomeBox is a home inventory and organization system. Prior to 0.26.0, HandleWipeInventory in backend/app/api/handlers/v1/v1_ctrl_actions.go authorizes POST /v1/actions/wipe-inventory through the global ctx.User.IsOwner value instead of the caller's role in the active group, while the active group is selected through the X-Tenant request header. Because every self-registered user who creates a group receives the global owner value, a user who is also a member of another group can select that group with X-Tenant and permanently delete its complete inventory, which is not recoverable without external backups. This issue is fixed in version 0.26.0.

Overview

State
PUBLISHED
Assigner (CNA)
GitHub_M
CVSS severity
HIGH
CVSS score
CVSS 8.1 / 10 8.1 8.1 / 10
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Effective score
8.1 / 10 HIGH source: CNA overview
CWE(s)
CWE-269, CWE-639
Reserved
2026-05-22
Published
2026-09-21 17:43 UTC
Last updated
2026-09-21 20:44 UTC
Source
https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/48xxx/CVE-2026-48826.json
Linked Threat
CVE-2026-48826 — HomeBox: Cross-Group Inventory Wipe in Homebox via Global Owner Role and X-Tenant Header Switching

NVD triage scoring NVD CVE 2.0

Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.

NVD published
2026-09-21 18:17:08 UTC
NVD last modified
2026-09-21 21:17:03 UTC
NVD CVSS v3.1
CVSS 8.1 / 10 8.1 8.1 / 10 HIGH source: security-advisories@github.com
NVD CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Exploitability subscore
2.8 / 10
Impact subscore
5.2 / 10

NVD / KEV / EPSS data refreshed 2026-09-22 03:40 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.

European Union Vulnerability Database ENISA EUVD

ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.

EUVD ID
EUVD-2026-84036
Assigner
GitHub_M
Published
Sep 21, 2026, 5:43:43 PM
Updated
Sep 21, 2026, 8:44:50 PM
EUVD base score (CVSS 3.1)
8.1 / 10
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
EUVD-reported EPSS
0.0000
Vendors
sysadminsmedia
Products
homebox (< 0.26.0)

ENISA description: HomeBox is a home inventory and organization system. Prior to 0.26.0, HandleWipeInventory in backend/app/api/handlers/v1/v1_ctrl_actions.go authorizes POST /v1/actions/wipe-inventory through the global ctx.User.IsOwner value instead of the caller's role in the active group, while the active group is selected through the X-Tenant request header. Because every self-registered user who creates a group receives the global owner value, a user who is also a member of another group can select that group with X-Tenant and permanently delete its complete inventory, which is not recoverable without external backups. This issue is fixed in version 0.26.0.

EUVD references (3)

Affected products (1)

VendorProductVersionsPlatforms
sysadminsmedia homebox < 0.26.0 (affected) —

Vendor references (3)

References embedded in the original CVE record by the assigning CNA.

Web references (0)

DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.

No web references attached yet.

NVD-tagged references (3)

Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.

Remediations (10)

Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.

  • web:blog.qualys.com

    Executive Summary CVE - 2026 -68820 is an actively exploited Windows vulnerability listed in CISA's Known Exploited Vulnerabilities (KEV) Catalog, with a remediation deadline as suggested by CISA BOD 26-04. CISA BOD 26-04 introduces risk-based remediation timelines ranging from 3 to 14 days, increasing the pressure on teams to move quickly from patch availability to verified remediation ...

    2026-09-22 16:48 UTC
  • web:cybersecuritynews.com

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued Binding Operational Directive (BOD) 26-04, titled "Prioritizing Security Updates Based on Risk," compelling all Federal Civilian Executive Branch (FCEB) agencies to remediate the most dangerous known exploited vulnerabilities within just three calendar days.

    2026-09-22 16:48 UTC
  • web:msrc.microsoft.com

    The Microsoft Security Response Center (MSRC) investigates all reports of security vulnerabilities affecting Microsoft products and services, and provides the information here as part of the ongoing effort to help you manage security risks and help keep your systems protected.

    2026-09-22 16:48 UTC
  • web:senserva.com

    Every Microsoft security patch (KB) and the CVEs it fixes, with severity, CVSS, and CISA KEV status. Cross-linked to the CVE reference.

    2026-09-22 16:48 UTC
  • web:tech-insider.org

    Microsoft patches 421 CVEs in August 2026 Patch Tuesday, including WinSock zero-day CVE - 2026 -68820 under active attack. Full breakdown here.

    2026-09-22 16:48 UTC
  • web:windowsforum.com

    The Windows entry is urgent, but the patch target is still missing A review of Microsoft's publicly indexed Security Update Guide material and NVD search results did not surface a record for CVE - 2026 -68820 when this article was prepared. That absence does not negate CISA's exploitation finding; disclosure and remediation pages frequently arrive after a KEV alert, are temporarily ...

    2026-09-22 16:48 UTC
  • web:www.aikido.dev

    None of these is a clean fix , which is why the decision on how to remediate depends on knowing what package versions are running in production and why. This post will cover how AI has accelerated CVE detection and discovery, the upgrade trap, what CVE remediation actually involves in 2026 , and how to solve the CVE remediation problem.

    2026-09-22 16:48 UTC
  • web:www.helpnetsecurity.com

    Microsoft's August 2026 Patch Tuesday delivered 400+ security fixes, including one for an actively exploited zero-day flaw ( CVE - 2026 -68820).

    2026-09-22 16:48 UTC
  • web:www.hivepro.com

    Microsoft's August 2026 Patch Tuesday addresses 423 vulnerabilities including the actively exploited Windows AFD.sys zero-day CVE - 2026 -68820. Priority CVEs , patch guidance, and IOCs inside.

    2026-09-22 16:48 UTC
  • web:www.tenable.com

    Microsoft patched 398 CVEs in August including three zero-day flaws, one exploited in the wild: CVE - 2026 -68820 in the Windows Ancillary Function Driver for WinSock.

    2026-09-22 16:48 UTC

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

Raw JSON

The full cvelistV5 record. Download as CVE-2026-48826.json.

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-48826",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-21T19:40:42.533804Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-21T20:44:50.012Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "homebox",
          "vendor": "sysadminsmedia",
          "versions": [
            {
              "status": "affected",
              "version": "< 0.26.0"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "HomeBox is a home inventory and organization system. Prior to 0.26.0, HandleWipeInventory in backend/app/api/handlers/v1/v1_ctrl_actions.go authorizes POST /v1/actions/wipe-inventory through the global ctx.User.IsOwner value instead of the caller's role in the active group, while the active group is selected through the X-Tenant request header. Because every self-registered user who creates a group receives the global owner value, a user who is also a member of another group can select that group with X-Tenant and permanently delete its complete inventory, which is not recoverable without external backups. This issue is fixed in version 0.26.0."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
            "version": "3.1"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-269",
              "description": "CWE-269: Improper Privilege Management",
              "lang": "en",
              "type": "CWE"
            }
          ]
        },
        {
          "descriptions": [
            {
              "cweId": "CWE-639",
              "description": "CWE-639: Authorization Bypass Through User-Controlled Key",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-21T17:43:43.510Z",
        "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "shortName": "GitHub_M"
      },
      "references": [
        {
          "name": "https://github.com/sysadminsmedia/homebox/security/advisories/GHSA-559j-7w3w-4fr7",
          "tags": [
            "x_refsource_CONFIRM"
          ],
          "url": "https://github.com/sysadminsmedia/homebox/security/advisories/GHSA-559j-7w3w-4fr7"
        },
        {
          "name": "https://github.com/sysadminsmedia/homebox/commit/ed3216a80998dfd81d4418700696244144883160",
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "https://github.com/sysadminsmedia/homebox/commit/ed3216a80998dfd81d4418700696244144883160"
        },
        {
          "name": "https://github.com/sysadminsmedia/homebox/releases/tag/v0.26.0",
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "https://github.com/sysadminsmedia/homebox/releases/tag/v0.26.0"
        }
      ],
      "source": {
        "advisory": "GHSA-559j-7w3w-4fr7",
        "discovery": "UNKNOWN"
      },
      "title": "HomeBox: Cross-Group Inventory Wipe in Homebox via Global Owner Role and X-Tenant Header Switching"
    }
  },
  "cveMetadata": {
    "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
    "assignerShortName": "GitHub_M",
    "cveId": "CVE-2026-48826",
    "datePublished": "2026-09-21T17:43:43.510Z",
    "dateReserved": "2026-05-22T20:57:10.977Z",
    "dateUpdated": "2026-09-21T20:44:50.012Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}