{"id":"CVE-2026-62252","title":"Homer is open source telecom observability software","summary":"Homer is open source telecom observability software. Prior to version 11.0.283, on every fresh Homer deployment using internal authentication, the bootstrap process automatically creates an `admin` account with the password `sipcapture` …","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-798"],"vendor":"sipcapture","product":"homer","affected":["homer < 11.0.283"],"patched":["github.com/sipcapture/homer-app 0.0.0-20260625091610-b2e942031ff8"],"published":"2026-10-07","updated":"2026-10-07","sourceUpdated":"2026-10-07T18:17:21.033","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-62252","references":[{"url":"https://github.com/sipcapture/homer/commit/b2e942031ff8cd7435a244ebef306ee97d16b809","label":"security-advisories@github.com"},{"url":"https://github.com/sipcapture/homer/pull/838","label":"security-advisories@github.com"},{"url":"https://github.com/sipcapture/homer/releases/tag/11.0.283","label":"security-advisories@github.com"},{"url":"https://github.com/sipcapture/homer/security/advisories/GHSA-6xp5-7rcx-xfgx","label":"security-advisories@github.com"},{"url":"https://github.com/sipcapture/homer/security/advisories/GHSA-6xp5-7rcx-xfgx","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://github.com/advisories/GHSA-6xp5-7rcx-xfgx"}],"tags":["nvd","cve.org","exploit-available","ghsa","go"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"yes","technicalImpact":"total","timestamp":"2026-10-07T17:43:45.414692Z"},"aliases":["GHSA-6xp5-7rcx-xfgx"],"ecosystem":"go","ingestedAt":"2026-10-07T16:38:22.236Z","slug":"CVE-2026-62252","body":"## Overview\n\nHomer is open source telecom observability software. Prior to version 11.0.283, on every fresh Homer deployment using internal authentication, the bootstrap process automatically creates an `admin` account with the password `sipcapture` (stored as a legacy SHA-256 hex hash). There is no first-login forced-change mechanism. Any attacker who reaches the login endpoint immediately gains full administrative access. Version 11.0.283 patches the issue.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-62252)\n\nAffected packages:\n\n- `github.com/sipcapture/homer-app < 0.0.0-20260625091610-b2e942031ff8`\n\nPatched in:\n\n- `github.com/sipcapture/homer-app 0.0.0-20260625091610-b2e942031ff8`\n\nSource: https://github.com/advisories/GHSA-6xp5-7rcx-xfgx","depth":"abyssal","depthScore":66,"depthScoreParts":{"impact":53.9,"likelihood":0,"exploitation":12,"ransomware":0},"changes":[{"seq":217653,"id":"CVE-2026-62252","ts":1791398601950,"field":"exploit_available","old":"false","new":"true"}]}