CVE-2026-62252
Homer is open source telecom observability software. Prior to version 11.0.283, on every fresh Homer deployment using internal authenticatio
CVSS
9.8
Critical
EPSS
0.7%
p50
KEV
—
Exploit Today
15
0-100
Published: Oct 7, 2026 · Last modified: Oct 8, 2026 · CWE-798
Not enough EPSS history yet.
Homer is open source telecom observability software. Prior to version 11.0.283, on every fresh Homer deployment using internal authentication, the bootstrap process automatically creates an `admin` account with the password `sipcapture` (stored as a legacy SHA-256 hex hash). There is no first-login forced-change mechanism. Any attacker who reaches the login endpoint immediately gains full administrative access. Version 11.0.283 patches the issue.
- github.comhttps://github.com/sipcapture/homer/commit/b2e942031ff8cd7435a244ebef306ee97d16b809
- github.comhttps://github.com/sipcapture/homer/pull/838
- github.comhttps://github.com/sipcapture/homer/releases/tag/11.0.283
- github.comhttps://github.com/sipcapture/homer/security/advisories/GHSA-6xp5-7rcx-xfgx
- github.comhttps://github.com/sipcapture/homer/security/advisories/GHSA-6xp5-7rcx-xfgx
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-848915.9 MED—
——0IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to obtain sensitive information due to use of hard-coded credentials.11hCVE-2026-842508.4 HIG—
——0IBM Guardium Data Protection 12.2 is vulnerable due to weak cryptographic protection and a hard-coded recovery key in the pkcrypto passkey component. A local attacker could exploit this vulnerability to recover the root password and gain root privileges.12hCVE-2026-85488—0.5%
——0Brocade ASCG before 3.5.0 has a well-known Brocade default password embedded in a script distributed to every customer. Any local authenticated user with read access to the installation path can discover this credential and perform privilege escalation on affected Open Virtual Appliance (OVA) deployments, where default configuration settings remain in place.13hCVE-2026-85422—1.0%
——0A vulnerability in Brocade ASCG version before 3.5.0 could allow an attacker to obtain a static cryptographic key hardcoded into the software binaries to secure sensitive data at rest and to protect inter-node communication protocols. An attacker who extracts this key can decrypt stored management credentials or craft forged administrative synchronization messages.13hCVE-2026-928614.0 MED1.2%
——0The Android application "Ticket Ryutsu Center" contains hard-coded credentials, which may allow an attacker to obtain an API key used by the application.12hCVE-2026-1021618.8 HIG11.0%
——3An unauthenticated attacker located on an adjacent private network (or any attacker routed through a reverse proxy/load balancer that forwards client headers) can forge their source IP address and gain administrative session privileges on the CV-CUE backend.2d