CVE-2026-48974: CWE-841: Improper Enforcement of Behavioral Workflow in sysadminsmedia homebox
HomeBox is a home inventory and organization system. Prior to 0.26.0, POST /v1/groups/members invokes HandleGroupMemberAdd and GroupService.AddMember using a caller-supplied userID without requiring an owner role, an invitation token, target-user consent, or target-user notification. Any authenticated user can force another account into the caller's group, disclose the target user's email address and name through the resulting member list, and create the membership prerequisite used by a separate cross-group inventory-wipe vulnerability. This issue is fixed in version 0.26.0.
AI Analysis
Technical Summary
The vulnerability in sysadminsmedia HomeBox before 0.26.0 involves improper enforcement of behavioral workflow in the group membership addition process. Specifically, the POST /v1/groups/members endpoint calls HandleGroupMemberAdd and GroupService.AddMember with a user-supplied userID but does not require the caller to have an owner role, an invitation token, or the target user's consent or notification. This allows any authenticated user to forcibly add another user to their group, exposing the target user's email and name via the member list. Additionally, this unauthorized membership can be leveraged as a prerequisite for a separate cross-group inventory-wipe vulnerability. The issue is resolved in version 0.26.0.
Potential Impact
An attacker with any authenticated account can add arbitrary users to their group without authorization, leading to disclosure of personal information (email and name) of the target users. This unauthorized group membership can also facilitate further attacks, such as a cross-group inventory wipe. The confidentiality and integrity of user group membership and associated data are impacted. There is no indication of availability impact.
Mitigation Recommendations
Upgrade to HomeBox version 0.26.0 or later, where this vulnerability is fixed. Prior versions do not enforce necessary authorization checks for group membership additions. No other mitigation or workaround is indicated.
CVE-2026-48974: CWE-841: Improper Enforcement of Behavioral Workflow in sysadminsmedia homebox
Description
HomeBox is a home inventory and organization system. Prior to 0.26.0, POST /v1/groups/members invokes HandleGroupMemberAdd and GroupService.AddMember using a caller-supplied userID without requiring an owner role, an invitation token, target-user consent, or target-user notification. Any authenticated user can force another account into the caller's group, disclose the target user's email address and name through the resulting member list, and create the membership prerequisite used by a separate cross-group inventory-wipe vulnerability. This issue is fixed in version 0.26.0.
CVSS v3.1
Score 5.4medium
Affected software
sysadminsmedia
homebox
pkg:github/sysadminsmedia/homeboxRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in sysadminsmedia HomeBox before 0.26.0 involves improper enforcement of behavioral workflow in the group membership addition process. Specifically, the POST /v1/groups/members endpoint calls HandleGroupMemberAdd and GroupService.AddMember with a user-supplied userID but does not require the caller to have an owner role, an invitation token, or the target user's consent or notification. This allows any authenticated user to forcibly add another user to their group, exposing the target user's email and name via the member list. Additionally, this unauthorized membership can be leveraged as a prerequisite for a separate cross-group inventory-wipe vulnerability. The issue is resolved in version 0.26.0.
Potential Impact
An attacker with any authenticated account can add arbitrary users to their group without authorization, leading to disclosure of personal information (email and name) of the target users. This unauthorized group membership can also facilitate further attacks, such as a cross-group inventory wipe. The confidentiality and integrity of user group membership and associated data are impacted. There is no indication of availability impact.
Mitigation Recommendations
Upgrade to HomeBox version 0.26.0 or later, where this vulnerability is fixed. Prior versions do not enforce necessary authorization checks for group membership additions. No other mitigation or workaround is indicated.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-26T23:26:07.974Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ab16d9855bf5e2cf5412e53
Added to database: 09/21/2026, 17:47:04 UTC
Last enriched: 09/21/2026, 18:01:52 UTC
Last updated: 09/21/2026, 23:40:28 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.