CVE-2026-48975 – HomeBox: Cross-Tenant IDOR in MaintenanceEntry Update and Delete Allows Tampering and Destruction of Any User’s Maintenance History in Homebox

​CVE ID :CVE-2026-48975

Published : Sept. 21, 2026, 6:17 p.m. | 42 minutes ago

Description :HomeBox is a home inventory and organization system. Prior to 0.26.0, MaintenanceEntryRepository.Update and MaintenanceEntryRepository.Delete in backend/internal/data/repo/repo_maintenance_entry.go use UpdateOneID(id) and DeleteOneID(id) without verifying that the maintenance entry belongs to the authenticated user’s active group. An authenticated low-privileged user who knows or enumerates another tenant’s maintenance-entry UUID can overwrite that record or permanently delete it. This issue is fixed in version 0.26.0.

Severity: 8.1 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more… To Read More Visit Read More