{"id":"CVE-2026-49994","title":"Bluehood monitors local bluetooth activity","summary":"Bluehood monitors local bluetooth activity. Prior to version 0.7.1, when auth_enabled is set in Bluehood, only the HTML page handlers enforced session validation. The /api/* handlers (settings, devices, groups, per-device endpoints inclu…","severity":"critical","cvss":9.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","cwe":["CWE-306","CWE-862"],"vendor":"dannymcc","product":"bluehood","affected":["bluehood < 0.7.1"],"published":"2026-09-28","updated":"2026-09-28","sourceUpdated":"2026-09-28T18:17:22.250","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-49994","references":[{"url":"https://github.com/dannymcc/bluehood/commit/401479938c0deb1f6f6847d442f98a2d03efca68","label":"security-advisories@github.com"},{"url":"https://github.com/dannymcc/bluehood/releases/tag/v0.7.1","label":"security-advisories@github.com"},{"url":"https://github.com/dannymcc/bluehood/security/advisories/GHSA-qj2j-wcg3-74jw","label":"security-advisories@github.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-28T18:17:54.310Z","slug":"CVE-2026-49994","body":"## Overview\n\nBluehood monitors local bluetooth activity. Prior to version 0.7.1, when auth_enabled is set in Bluehood, only the HTML page handlers enforced session validation. The /api/* handlers (settings, devices, groups, per-device endpoints including /api/device/{mac}/notes) called no auth check at all. A network attacker reachable on the dashboard port could read Bluetooth tracking data and modify application state — including the heartbeat URL, prune retention, device groups, and per-device notes — without a session cookie. This issue has been patched in version 0.7.1.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":50,"depthScoreParts":{"impact":50.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}