{"id":"CVE-2026-48975","title":"HomeBox: Cross-Tenant IDOR in MaintenanceEntry Update and Delete Allows Tampering and Destruction of Any User's Maintenance   History in Homebox","summary":"HomeBox is a home inventory and organization system. Prior to 0.26.0, MaintenanceEntryRepository.Update and MaintenanceEntryRepository.Delete in backend/internal/data/repo/repo_maintenance_entry.go use UpdateOneID(id) and DeleteOneID(id)…","severity":"high","cvss":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","cvssSource":"cna","cwe":["CWE-639"],"vendor":"sysadminsmedia","product":"homebox","affected":["homebox < 0.26.0"],"published":"2026-09-21","updated":"2026-09-21","sourceUpdated":"2026-09-21T17:42:14.826Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-48975","references":[{"url":"https://github.com/sysadminsmedia/homebox/security/advisories/GHSA-7mr6-2wxw-27j9","label":"https://github.com/sysadminsmedia/homebox/security/advisories/GHSA-7mr6-2wxw-27j9"},{"url":"https://github.com/sysadminsmedia/homebox/commit/ed3216a80998dfd81d4418700696244144883160","label":"https://github.com/sysadminsmedia/homebox/commit/ed3216a80998dfd81d4418700696244144883160"},{"url":"https://github.com/sysadminsmedia/homebox/releases/tag/v0.26.0","label":"https://github.com/sysadminsmedia/homebox/releases/tag/v0.26.0"}],"tags":["cve.org"],"ingestedAt":"2026-09-21T17:49:53.176Z","slug":"CVE-2026-48975","body":"## Overview\n\nHomeBox is a home inventory and organization system. Prior to 0.26.0, MaintenanceEntryRepository.Update and MaintenanceEntryRepository.Delete in backend/internal/data/repo/repo_maintenance_entry.go use UpdateOneID(id) and DeleteOneID(id) without verifying that the maintenance entry belongs to the authenticated user's active group. An authenticated low-privileged user who knows or enumerates another tenant's maintenance-entry UUID can overwrite that record or permanently delete it. This issue is fixed in version 0.26.0.\n\n## Affected\n\n- `homebox < 0.26.0`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":44.6,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}