PT-2026-28466 · Unknown · Home Assistant

Pwnpanda

·

Published

2026-03-27

·

Updated

2026-03-29

·

CVE-2026-33044

CVSS v4.0

8.8

High

VectorAV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Home Assistant versions 2020.02 through 2026.01
Description Home Assistant, an open-source home automation software, contains a flaw where an authenticated user can inject malicious code into a device entity name. This allows for Cross-Site Scripting (XSS) attacks against other users who view a dashboard containing a Map-card that includes the compromised entity. The attack requires the victim to hover over an information point on the map. The issue is similar to a previously documented issue but affects entities displayed in a Map, rather than an energy dashboard. The impact of this flaw allows a user to potentially target other users and perform account takeover through client-side exploitation.
Recommendations Update to version 2026.01 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-33044
GHSA-R584-6283-P7XC

Affected Products

Home Assistant