CVE-2026-48826High· 8.1▾ TwilightHomeBox is a home inventory and organization system. Prior to 0.26.0, HandleWipeInventory in backend/app/api/handlers/v1/v1_ctrl_actions.go authorizes POST /v1/actions/wipe-inventory through the global ctx.User.IsOwner value instead of t…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44.6 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
HomeBox is a home inventory and organization system. Prior to 0.26.0, HandleWipeInventory in backend/app/api/handlers/v1/v1_ctrl_actions.go authorizes POST /v1/actions/wipe-inventory through the global ctx.User.IsOwner value instead of the caller's role in the active group, while the active group is selected through the X-Tenant request header. Because every self-registered user who creates a group receives the global owner value, a user who is also a member of another group can select that group with X-Tenant and permanently delete its complete inventory, which is not recoverable without external backups. This issue is fixed in version 0.26.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-48976High· 8.1HomeBox is a home inventory and organization system
CVE-2026-48975High· 8.1HomeBox is a home inventory and organization system
CVE-2026-48974Medium· 5.4HomeBox is a home inventory and organization system
CVE-2026-55473Medium· 6.0HomeBox is a home inventory and organization system
CVE-2026-15630Critical· 9.9CVE-2026-15630
CVE-2026-72863Critical· 9.9Dokploy is a free, self-hostable Platform as a Service (PaaS)