Homer VoIP Monitor: Default Install Ships With Complete Authentication Bypass (CVE-2026-62253)
What Happened
A GitHub Security Advisory (GHSA-rqcc-94gv-wjm9) discloses a critical authentication bypass in Homer, the open-source SIP/VoIP capture and monitoring platform (github.com/sipcapture/homer-app). According to the advisory, both JWT middleware implementations (JWTMiddleware and JWTMiddlewareV4 in coordinator/handlers/auth.go and auth_v4_helpers.go) immediately call next(c) and skip token validation whenever jwtSecret == "". Because the Go struct default for JWT.Secret is an empty string, a default installation with no operator-configured secret leaves every protected endpoint under /api/v1, /api/v3, and /api/v4 completely unauthenticated. The advisory includes a working PoC showing unauthenticated reads of the user list and database connection strings, plus unauthenticated creation of a new admin user via a simple curl POST. The issue has been assigned CVE-2026-62253 with a reported CVSS of 9.8, and a public PoC is already available.
Why It Matters
Homer is used to centrally capture and store VoIP/SIP call metadata and signaling, so the data exposed here is sensitive by nature — stored call records, database credentials, and full admin configuration control. The root cause is a fail-open design: the middleware is not merely misconfigured, it is not registered at all when no secret is set (per the advisory's reference to coordinator.go), so there's no authentication layer to bypass — there simply isn't one. Any installation that hasn't explicitly set a strong coordinator.jwt.secret — which the advisory indicates is plausible given the shipped example config uses only a placeholder — is exposed to full read/write admin access with zero credentials.
What Defenders Should Do Now
- Treat this as urgent for any environment running Homer/homer-app: verify
coordinator.jwt.secret(or equivalent JWT secret config) is set to a non-empty, strong value, not left at its default. - Until a patched release is confirmed, consider taking Homer's API endpoints off any public or broadly-reachable network segment and restricting access to trusted hosts only.
- Audit logs/network traffic for unauthenticated calls to
/api/v1,/api/v3, or/api/v4endpoints (e.g./api/v3/users,/api/v3/databases) originating from unexpected source IPs, and specifically look for anomalousPOSTrequests creating new users withusergroup: admin. - Review the existing user list for any unrecognized admin accounts that may have already been created via this path.
- Track vendor remediation — the advisory recommends the fix fail closed (fatal error at startup if the secret is empty) rather than silently bypassing auth.
Developing Intel
This is a same-day, net-new advisory; full detail on affected version ranges and official patch availability was not included in the material reviewed here. We'll track this for updates. Full details: GHSA-rqcc-94gv-wjm9.