CVE-2026-62252
Received Received - Intake

Hard-Coded Admin Credentials in Homer

Vulnerability report for CVE-2026-62252, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: GitHub, Inc.

Description

Homer is open source telecom observability software. Prior to version 11.0.283, on every fresh Homer deployment using internal authentication, the bootstrap process automatically creates an `admin` account with the password `sipcapture` (stored as a legacy SHA-256 hex hash). There is no first-login forced-change mechanism. Any attacker who reaches the login endpoint immediately gains full administrative access. Version 11.0.283 patches the issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
sipcapture homer < 11.0.283

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-798 The product contains hard-coded credentials, such as a password or cryptographic key.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-62252 is a vulnerability in Homer, an open-source telecom observability tool. On fresh deployments using internal authentication, the system automatically creates an admin account with the password 'sipcapture' stored as a legacy SHA-256 hash. No forced password change is required, allowing immediate full administrative access to anyone reaching the login endpoint.

Detection Guidance

Check Homer deployments for the presence of an admin account with the password sipcapture. Inspect configuration files for hardcoded admin credentials or legacy SHA-256 hashes. Verify if the admin password was auto-generated or manually set during bootstrap.

Impact Analysis

An attacker who gains network access to a vulnerable Homer deployment can exploit this to log in as admin with full privileges without needing to guess or crack the password. This could lead to unauthorized system control, data exfiltration, or further network compromise. The high CVSS score (9.8) reflects the severe potential impact.

Compliance Impact

This vulnerability likely violates compliance requirements for access controls and data protection in standards like GDPR and HIPAA. It enables unauthorized administrative access, which could lead to unauthorized data access, processing, or disclosure, violating confidentiality and integrity requirements mandated by these regulations.

Mitigation Strategies

Upgrade Homer to version 11.0.283 or later to remove the hardcoded password. If upgrading is not possible, manually set a strong admin password via configuration or the setup wizard. Ensure no legacy SHA-256 hashes for sipcapture remain in use.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-62252. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart