CVE-2026-66061: CWE-862: Missing Authorization in home-assistant core
Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.5.0, the iOS Companion app treats tag links (NFC or QR) delivered through an OS-level routing mechanism such as iOS universal links as if they were physically scanned, without validating the calling app or prompting the user. As a result, any untrusted app on the device can forward an arbitrary tag to Home Assistant, causing it to execute the associated automation as though a legitimate user had scanned an authorized tag. This allows silent, unattended automation execution by untrusted local callers. This issue has been fixed in version 2026.5.0.
AI Analysis
Technical Summary
Home Assistant core versions before 2026.5.0 contain a missing authorization vulnerability (CWE-862) in the iOS Companion app. The app treats tag links delivered via OS-level routing mechanisms such as iOS universal links as if they were physically scanned, without validating the calling app or prompting the user. Consequently, any untrusted app on the device can forward arbitrary tag data to Home Assistant, causing it to execute associated automations silently and unattended. This vulnerability allows unauthorized local callers to trigger automations without user consent. The issue is resolved in version 2026.5.0.
Potential Impact
An attacker with an untrusted app on the same iOS device can silently trigger Home Assistant automations without user interaction or authorization. This can lead to unauthorized automation execution, potentially causing security or privacy risks depending on the automation's function. There is no impact on confidentiality or availability reported, but integrity is impacted due to unauthorized automation execution.
Mitigation Recommendations
Upgrade Home Assistant core to version 2026.5.0 or later, where this vulnerability has been fixed. Prior to upgrading, be cautious about installing untrusted iOS apps that might exploit this issue. No other official remediation or temporary fixes are documented.
CVE-2026-66061: CWE-862: Missing Authorization in home-assistant core
Description
Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.5.0, the iOS Companion app treats tag links (NFC or QR) delivered through an OS-level routing mechanism such as iOS universal links as if they were physically scanned, without validating the calling app or prompting the user. As a result, any untrusted app on the device can forward an arbitrary tag to Home Assistant, causing it to execute the associated automation as though a legitimate user had scanned an authorized tag. This allows silent, unattended automation execution by untrusted local callers. This issue has been fixed in version 2026.5.0.
CVSS v3.1
Score 7.1high
Affected software
home-assistant
core
pkg:github/home-assistant/coreRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Home Assistant core versions before 2026.5.0 contain a missing authorization vulnerability (CWE-862) in the iOS Companion app. The app treats tag links delivered via OS-level routing mechanisms such as iOS universal links as if they were physically scanned, without validating the calling app or prompting the user. Consequently, any untrusted app on the device can forward arbitrary tag data to Home Assistant, causing it to execute associated automations silently and unattended. This vulnerability allows unauthorized local callers to trigger automations without user consent. The issue is resolved in version 2026.5.0.
Potential Impact
An attacker with an untrusted app on the same iOS device can silently trigger Home Assistant automations without user interaction or authorization. This can lead to unauthorized automation execution, potentially causing security or privacy risks depending on the automation's function. There is no impact on confidentiality or availability reported, but integrity is impacted due to unauthorized automation execution.
Mitigation Recommendations
Upgrade Home Assistant core to version 2026.5.0 or later, where this vulnerability has been fixed. Prior to upgrading, be cautious about installing untrusted iOS apps that might exploit this issue. No other official remediation or temporary fixes are documented.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-07-23T23:25:28.896Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a764a22bf8831d53929f638
Added to database: 08/07/2026, 21:12:02 UTC
Last enriched: 08/15/2026, 15:33:14 UTC
Last updated: 09/22/2026, 01:52:45 UTC
Views: 82
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.