CVE-2026-48974 | sysadminsmedia HomeBox up to 0.25.x Group Member Management /v1/groups/members GroupService.AddMember userID information disclosure

SecurityVulns

A vulnerability identified as problematic has been detected in sysadminsmedia HomeBox up to 0.25.x. Impacted is the function GroupService.AddMember of the file /v1/groups/members of the component Group Member Management. This manipulation of the argument userID causes information disclosure.

This vulnerability appears as CVE-2026-48974. The attack may be initiated remotely. There is no available exploit.

You should upgrade the affected component.VulDB Recent EntriesRead More