CVE-2026-66060 | home-assistant Home Assistant up to 2026.5.2 Companion App improper authorization (EUVD-2026-54654)

SecurityVulns

A vulnerability described as problematic has been identified in home-assistant Home Assistant up to 2026.5.2. Affected by this vulnerability is an unknown functionality of the component Companion App. Executing a manipulation can lead to improper authorization.

This vulnerability is tracked as CVE-2026-66060. The attack is restricted to local execution. No exploit exists.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More