PatchSiren

esphome CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM esphome CVE published 2026-08-05

CVE-2026-71260

The ESPHome web_server component discloses plaintext passwords via its text_json_() function, allowing an attacker on the local network to retrieve sensitive information via GET /text/<entity_id> or the /events EventSource stream. This vulnerability affects ESPHome versions up to 2026.7.0-dev and has a CVSS score of 6.5 (MEDIUM severity). The vulnerability is caused by a text entity configured with mode: [truncated]