Critical severity9.8NVD Advisory· Published Oct 7, 2026
CVE-2026-62252
CVE-2026-62252
Description
Homer is open source telecom observability software. Prior to version 11.0.283, on every fresh Homer deployment using internal authentication, the bootstrap process automatically creates an admin account with the password sipcapture (stored as a legacy SHA-256 hex hash). There is no first-login forced-change mechanism. Any attacker who reaches the login endpoint immediately gains full administrative access. Version 11.0.283 patches the issue.
Affected products
1- Range: <11.0.283
Patches
Vulnerability mechanics
References
5News mentions
0No linked articles in our index yet.