---
id: CVE-2026-49994
title: Bluehood monitors local bluetooth activity
summary: >-
  Bluehood monitors local bluetooth activity. Prior to version 0.7.1, when
  auth_enabled is set in Bluehood, only the HTML page handlers enforced session
  validation. The /api/* handlers (settings, devices, groups, per-device
  endpoints inclu…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-306
  - CWE-862
vendor: dannymcc
product: bluehood
affected:
  - bluehood < 0.7.1
published: '2026-09-28'
updated: '2026-09-28'
sourceUpdated: '2026-09-28T18:17:22.250'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-49994'
references:
  - url: >-
      https://github.com/dannymcc/bluehood/commit/401479938c0deb1f6f6847d442f98a2d03efca68
    label: security-advisories@github.com
  - url: 'https://github.com/dannymcc/bluehood/releases/tag/v0.7.1'
    label: security-advisories@github.com
  - url: >-
      https://github.com/dannymcc/bluehood/security/advisories/GHSA-qj2j-wcg3-74jw
    label: security-advisories@github.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-28T18:17:54.310Z'
---

## Overview

Bluehood monitors local bluetooth activity. Prior to version 0.7.1, when auth_enabled is set in Bluehood, only the HTML page handlers enforced session validation. The /api/* handlers (settings, devices, groups, per-device endpoints including /api/device/{mac}/notes) called no auth check at all. A network attacker reachable on the dashboard port could read Bluetooth tracking data and modify application state — including the heartbeat URL, prune retention, device groups, and per-device notes — without a session cookie. This issue has been patched in version 0.7.1.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
