PatchSiren

sysadminsmedia CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM sysadminsmedia CVE published 2026-09-21

CVE-2026-55473

An authenticated user can submit a crafted notifier through POST /v1/notifiers or POST /v1/notifiers/test, potentially disclosing retrieved metadata such as temporary credentials on a Homebox instance that egresses through NAT64/DNS64. This medium-severity vulnerability affects Homebox instances with notifier features in use, particularly those with NAT64/DNS64 egress configurations. Defenders should asse [truncated]

MEDIUM sysadminsmedia CVE published 2026-09-21

CVE-2026-48974

CVE-2026-48974 is a vulnerability in HomeBox, a home inventory and organization system, prior to version 0.26.0. The vulnerability allows any authenticated user to force another account into the caller's group, disclose the target user's email address and name, and create a membership prerequisite for a separate cross-group inventory-wipe vulnerability. This issue is fixed in version 0.26.0.