By vendor
Home-Assistant vulnerabilities
Known CVEs affecting Home-Assistant products, prioritized by severity, with SEC.co remediation and detection guidance.
2 published vulnerabilities
- CVE-2026-54317HIGH 7.6
Home Assistant, a popular open-source home automation platform, contains an authentication bypass in its Konnected integration prior to version 2026.6.0. The integration exposes an HTTP endpoint that should verify API access tokens, but the verification logic only applies to write operations (POST, PUT). Read operations (GET) lack any authentication check entirely, allowing unauthenticated attackers on the local network to retrieve sensitive sensor data and configuration details.
- CVE-2026-54318HIGH 7.1
Home Assistant's companion app for Android contains a flaw that allows any installed application to spoof your device's GPS location without needing special permissions. An attacker can trick Home Assistant into believing you're at a different location than where you actually are, potentially triggering automations tied to your real-world position—such as unlocking doors, disarming alarms, or opening garages. Because this vulnerability bypasses Android's built-in mock location protections, even apps that appear benign could exploit it. The issue is fixed in version 2026.5.3.