Vulnerability
Published 2026-06-25
Verified 2026-10-08

Homer (SIPCAPTURE) telecom observability: CVE records published for a default empty JWT secret that leaves every API unauthenticated (CVE-2026-62253, 9.8) and a default admin password 'sipcapture' (CVE-2026-62252, 9.8); fixed in 11.0.283

CVE records were published on 7 October 2026 for three flaws in Homer, the open-source SIP and VoIP capture and troubleshooting platform from the SIPCAPTURE project, used by carriers and VoIP operators. The project fixed them in Homer 11.0.283 and published GitHub security advisories on 25 June 2026. CVE-2026-62253 (GHSA-rqcc-94gv-wjm9, CVSS 3.1 9.8): both JWT middleware functions let a request through when the JWT secret is empty, and the secret defaults to empty, so on a default install all protected API endpoints under /api/v1, /api/v3 and /api/v4 need no login. CVE-2026-62252 (GHSA-6xp5-7rcx-xfgx, 9.8): fresh deployments using internal authentication create an admin account with the password 'sipcapture' and never force a change, so anyone who reaches the login page gets full admin access. CVE-2026-62251 (GHSA-f46q-3v67-fmm4, 8.1): any authenticated user can send raw SQL to DuckDB through the v4 statistics query endpoint and read or change everything reachable through the FlightSQL service. Homer stores captured call signalling, which includes phone numbers and call metadata. No exploitation has been reported. Primary: SIPCAPTURE GitHub security advisories and CVE records.

Product
Homer (SIPCAPTURE) SIP/VoIP capture and telecom observability platform
Versions
Homer before 11.0.283
CVSS
Critical (CVE-2026-62253 and CVE-2026-62252); 8.1 (CVE-2026-62251), CVSS 3.1
Exploited in Australia?
unknown
Patch to
Upgrade Homer to 11.0.283 or later. Set a long random coordinator.jwt.secret, change the admin password, and keep the Homer web interface and API off the internet behind VPN or management-network access. If an instance ran a default configuration while reachable, treat captured call data as exposed and review accounts and API access logs.

Primary: SIPCAPTURE — GHSA-rqcc-94gv-wjm9: complete authentication bypass when coordinator.jwt.secret is empty (default), CVE-2026-62253 (25 Jun 2026) · Vendor: SIPCAPTURE — GHSA-6xp5-7rcx-xfgx: hardcoded default admin password with no forced change, CVE-2026-62252 · CVE: CVE-2026-62253, CVE-2026-62252, CVE-2026-62251 · CVE record — CVE-2026-62253 (published 7 Oct 2026)

vulnerabilities network