PatchSiren cyber security CVE debrief
CVE-2026-64825 home-assistant CVE debrief
Home Assistant Core before version 2026.6.0 contains a path traversal vulnerability that allows unauthenticated attackers to write arbitrary files to any directory on the host filesystem by uploading a crafted backup archive during the initial onboarding window. This vulnerability can be exploited by manipulating the 'name' field inside the uploaded archive's backup.json to supply an absolute path, potentially leading to full filesystem access when the process runs as root. Defenders should assess their exposure and prioritize verification and remediation.
- Vendor
- home-assistant
- Product
- Home Assistant Core
- CVSS
- CRITICAL 9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for Home Assistant Core installations, especially those with exposed instances, should assess their exposure and prioritize verification and remediation. This includes operators, security teams, and vulnerability management teams. They should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
Why it matters
This vulnerability allows unauthenticated attackers to write arbitrary files to any directory on the host filesystem, potentially leading to full filesystem access when the process runs as root.
- Verify and upgrade to version 2026.6.0 or later to prevent arbitrary file writes
- Restrict access to the initial onboarding window to limit attack surface
- Monitor for suspicious backup archive uploads to detect potential attacks
Technical summary
The vulnerability is caused by a path traversal issue in the backup archive upload feature, allowing attackers to manipulate the 'name' field inside the uploaded archive's backup.json to supply an absolute path. This can lead to arbitrary file writes on the host filesystem, potentially resulting in full filesystem access when the process runs as root. The issue is fixed in version 2026.6.0 or later. Defenders should prioritize verifying and upgrading to the latest version. The vulnerability has a CVSS score of 9 and a severity of CRITICAL.
Defensive priority
Defenders should prioritize verifying and upgrading to version 2026.6.0 or later, and restrict access to the initial onboarding window.
Recommended defensive actions
- Verify and upgrade to version 2026.6.0 or later
- Restrict access to the initial onboarding window
- Monitor for suspicious backup archive uploads
- Review compensating controls for exposed systems
- Check relevant monitoring, detection, and logs for exposed assets
- Track exceptions and retest remediated assets
- Confirm whether affected product deployments exist in managed environments
Evidence notes
The vulnerability allows unauthenticated attackers to write arbitrary files to any directory on the host filesystem by uploading a crafted backup archive during the initial onboarding window. Evidence is limited to the supplied CVE record and source item details. Defenders should verify the affected scope and prioritize remediation. The CVE record was published on 2026-07-21T15:40:18.756Z and has not been modified since then.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-64825 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-64825
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-64825 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-64825
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Home Assistant Core < 2026.6.0 Path Traversal File Write via Backup Upload
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/64xxx/CVE-2026-64825.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/home-assistant/core/releases/tag/2026.6.0
Supplemental source - release-notes
-
Source reference
Unverified legacy reference
URL: https://github.com/home-assistant/core/pull/172368
Supplemental source - issue-tracking
-
Source reference
Unverified legacy reference
URL: https://github.com/home-assistant/core/commit/567fe858289876b68b8162a77bd46e1e1af79752
Supplemental source - patch
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/home-assistant-core-path-traversal-file-write-via-backup-upload
Supplemental source - third-party-advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.