PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-64825 home-assistant CVE debrief

Home Assistant Core before version 2026.6.0 contains a path traversal vulnerability that allows unauthenticated attackers to write arbitrary files to any directory on the host filesystem by uploading a crafted backup archive during the initial onboarding window. This vulnerability can be exploited by manipulating the 'name' field inside the uploaded archive's backup.json to supply an absolute path, potentially leading to full filesystem access when the process runs as root. Defenders should assess their exposure and prioritize verification and remediation.

Vendor
home-assistant
Product
Home Assistant Core
CVSS
CRITICAL 9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-10-08
Advisory published
2026-07-21
Advisory updated
2026-10-08

Who should care

Defenders responsible for Home Assistant Core installations, especially those with exposed instances, should assess their exposure and prioritize verification and remediation. This includes operators, security teams, and vulnerability management teams. They should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.

Why it matters

This vulnerability allows unauthenticated attackers to write arbitrary files to any directory on the host filesystem, potentially leading to full filesystem access when the process runs as root.

  • Verify and upgrade to version 2026.6.0 or later to prevent arbitrary file writes
  • Restrict access to the initial onboarding window to limit attack surface
  • Monitor for suspicious backup archive uploads to detect potential attacks

Technical summary

The vulnerability is caused by a path traversal issue in the backup archive upload feature, allowing attackers to manipulate the 'name' field inside the uploaded archive's backup.json to supply an absolute path. This can lead to arbitrary file writes on the host filesystem, potentially resulting in full filesystem access when the process runs as root. The issue is fixed in version 2026.6.0 or later. Defenders should prioritize verifying and upgrading to the latest version. The vulnerability has a CVSS score of 9 and a severity of CRITICAL.

Defensive priority

Defenders should prioritize verifying and upgrading to version 2026.6.0 or later, and restrict access to the initial onboarding window.

Recommended defensive actions

  • Verify and upgrade to version 2026.6.0 or later
  • Restrict access to the initial onboarding window
  • Monitor for suspicious backup archive uploads
  • Review compensating controls for exposed systems
  • Check relevant monitoring, detection, and logs for exposed assets
  • Track exceptions and retest remediated assets
  • Confirm whether affected product deployments exist in managed environments

Evidence notes

The vulnerability allows unauthenticated attackers to write arbitrary files to any directory on the host filesystem by uploading a crafted backup archive during the initial onboarding window. Evidence is limited to the supplied CVE record and source item details. Defenders should verify the affected scope and prioritize remediation. The CVE record was published on 2026-07-21T15:40:18.756Z and has not been modified since then.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-64825 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-64825

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-64825 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-64825

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Home Assistant Core < 2026.6.0 Path Traversal File Write via Backup Upload

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/64xxx/CVE-2026-64825.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/home-assistant/core/releases/tag/2026.6.0

    Supplemental source - release-notes

  • Source reference

    Unverified legacy reference

    URL: https://github.com/home-assistant/core/pull/172368

    Supplemental source - issue-tracking

  • Source reference

    Unverified legacy reference

    URL: https://github.com/home-assistant/core/commit/567fe858289876b68b8162a77bd46e1e1af79752

    Supplemental source - patch

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/home-assistant-core-path-traversal-file-write-via-backup-upload

    Supplemental source - third-party-advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.