PT-2026-28606 · Unknown · Home Assistant

Published

2026-03-27

·

Updated

2026-04-02

·

CVE-2026-34205

CVSS v3.1

9.6

Critical

VectorAV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Home Assistant versions prior to 2026.03.02
Description Home Assistant is open source home automation software focused on local control and privacy. Home Assistant apps, when configured with host network mode, expose unauthenticated endpoints bound to the internal Docker bridge interface to the local network. This configuration does not restrict access to the app as intended, allowing any device on the same network to reach these endpoints without authentication.
Recommendations Update to Home Assistant Supervisor version 2026.03.02 or later.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2026-34205

Affected Products

Home Assistant