{"api_version":"1","generated_at":"2026-09-22T09:30:41+00:00","cve":"CVE-2026-48974","urls":{"html":"https://cve.report/CVE-2026-48974","api":"https://cve.report/api/cve/CVE-2026-48974.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-48974","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-48974"},"summary":{"title":"HomeBox: Forced Group Membership Without Consent in Homebox AddMember Handler","description":"HomeBox is a home inventory and organization system. Prior to 0.26.0, POST /v1/groups/members invokes HandleGroupMemberAdd and GroupService.AddMember using a caller-supplied userID without requiring an owner role, an invitation token, target-user consent, or target-user notification. Any authenticated user can force another account into the caller's group, disclose the target user's email address and name through the resulting member list, and create the membership prerequisite used by a separate cross-group inventory-wipe vulnerability. This issue is fixed in version 0.26.0.","state":"PUBLISHED","assigner":"GitHub_M","published_at":"2026-09-21 18:17:08","updated_at":"2026-09-21 18:17:08"},"problem_types":["CWE-841","CWE-862","CWE-841 CWE-841: Improper Enforcement of Behavioral Workflow","CWE-862 CWE-862: Missing Authorization"],"metrics":[{"version":"3.1","source":"security-advisories@github.com","type":"Secondary","score":"5.4","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"5.4","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","version":"3.1"}}],"references":[{"url":"https://github.com/sysadminsmedia/homebox/releases/tag/v0.26.0","name":"https://github.com/sysadminsmedia/homebox/releases/tag/v0.26.0","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/sysadminsmedia/homebox/security/advisories/GHSA-ffcw-whqh-hgqf","name":"https://github.com/sysadminsmedia/homebox/security/advisories/GHSA-ffcw-whqh-hgqf","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/sysadminsmedia/homebox/commit/ed3216a80998dfd81d4418700696244144883160","name":"https://github.com/sysadminsmedia/homebox/commit/ed3216a80998dfd81d4418700696244144883160","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-48974","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48974","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"sysadminsmedia","product":"homebox","version":"affected < 0.26.0","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"product":"homebox","vendor":"sysadminsmedia","versions":[{"status":"affected","version":"< 0.26.0"}]}],"descriptions":[{"lang":"en","value":"HomeBox is a home inventory and organization system. Prior to 0.26.0, POST /v1/groups/members invokes HandleGroupMemberAdd and GroupService.AddMember using a caller-supplied userID without requiring an owner role, an invitation token, target-user consent, or target-user notification. Any authenticated user can force another account into the caller's group, disclose the target user's email address and name through the resulting member list, and create the membership prerequisite used by a separate cross-group inventory-wipe vulnerability. This issue is fixed in version 0.26.0."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","version":"3.1"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-841","description":"CWE-841: Improper Enforcement of Behavioral Workflow","lang":"en","type":"CWE"}]},{"descriptions":[{"cweId":"CWE-862","description":"CWE-862: Missing Authorization","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-21T17:42:59.002Z","orgId":"a0819718-46f1-4df5-94e2-005712e83aaa","shortName":"GitHub_M"},"references":[{"name":"https://github.com/sysadminsmedia/homebox/security/advisories/GHSA-ffcw-whqh-hgqf","tags":["x_refsource_CONFIRM"],"url":"https://github.com/sysadminsmedia/homebox/security/advisories/GHSA-ffcw-whqh-hgqf"},{"name":"https://github.com/sysadminsmedia/homebox/commit/ed3216a80998dfd81d4418700696244144883160","tags":["x_refsource_MISC"],"url":"https://github.com/sysadminsmedia/homebox/commit/ed3216a80998dfd81d4418700696244144883160"},{"name":"https://github.com/sysadminsmedia/homebox/releases/tag/v0.26.0","tags":["x_refsource_MISC"],"url":"https://github.com/sysadminsmedia/homebox/releases/tag/v0.26.0"}],"source":{"advisory":"GHSA-ffcw-whqh-hgqf","discovery":"UNKNOWN"},"title":"HomeBox: Forced Group Membership Without Consent in Homebox AddMember Handler"}},"cveMetadata":{"assignerOrgId":"a0819718-46f1-4df5-94e2-005712e83aaa","assignerShortName":"GitHub_M","cveId":"CVE-2026-48974","datePublished":"2026-09-21T17:42:59.002Z","dateReserved":"2026-05-26T23:26:07.974Z","dateUpdated":"2026-09-21T17:42:59.002Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-21 18:17:08","lastModifiedDate":"2026-09-21 18:17:08","problem_types":["CWE-841","CWE-862","CWE-841 CWE-841: Improper Enforcement of Behavioral Workflow","CWE-862 CWE-862: Missing Authorization"],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.5}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"48974","Ordinal":"1","Title":"HomeBox: Forced Group Membership Without Consent in Homebox AddM","CVE":"CVE-2026-48974","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"48974","Ordinal":"1","NoteData":"HomeBox is a home inventory and organization system. Prior to 0.26.0, POST /v1/groups/members invokes HandleGroupMemberAdd and GroupService.AddMember using a caller-supplied userID without requiring an owner role, an invitation token, target-user consent, or target-user notification. Any authenticated user can force another account into the caller's group, disclose the target user's email address and name through the resulting member list, and create the membership prerequisite used by a separate cross-group inventory-wipe vulnerability. This issue is fixed in version 0.26.0.","Type":"Description","Title":"HomeBox: Forced Group Membership Without Consent in Homebox AddM"}]}}}