CVE-2026-62252Critical· 9.8▾ MidnightHomer is open source telecom observability software. Prior to version 11.0.283, on every fresh Homer deployment using internal authentication, the bootstrap process automatically creates an `admin` account with the password `sipcapture` …
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Homer is open source telecom observability software. Prior to version 11.0.283, on every fresh Homer deployment using internal authentication, the bootstrap process automatically creates an admin account with the password sipcapture (stored as a legacy SHA-256 hex hash). There is no first-login forced-change mechanism. Any attacker who reaches the login endpoint immediately gains full administrative access. Version 11.0.283 patches the issue.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
github.com/sipcapture/homer-app < 0.0.0-20260625091610-b2e942031ff8Patched in:
github.com/sipcapture/homer-app 0.0.0-20260625091610-b2e942031ff8Connected by shared product, vendor, weakness, or advisory.
CVE-2026-62253Critical· 9.8Homer is open source telecom observability software
CVE-2026-62251High· 8.1Homer is open source telecom observability software
CVE-2026-63406Medium· 5.9AnyCable is a realtime server for reliable two-way communication that supports any backend
CVE-2019-6693Medium· 6.5Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive data, via knowledge of the hard-coded key
CVE-2024-23687Critical· 9.1Hard-coded credentials in FOLIO mod-data-export-spring versions before 1.5.4 and from 2.0.0 to 2.0.2 allows unauthenticated users to access critical APIs, modify user data, modify configurations including single-sign-on, and manipulate f…
CVE-2024-23685Medium· 5.3Hard-coded credentials in mod-remote-storage versions under 1.7.2 and from 2.0.0 to 2.0.3 allows unauthorized users to gain read access to mod-inventory-storage records including instances, holdings, items, contributor-types, and identif…