CVE-2026-48975 | sysadminsmedia HomeBox up to 0.25.9 Maintenance Entry Repository repo_maintenance_entry.go ID privileges management
A vulnerability classified as problematic has been found in sysadminsmedia HomeBox up to 0.25.9. This impacts the function MaintenanceEntryRepository.Update/MaintenanceEntryRepository.Delete of the file backend/internal/data/repo/repo_maintenance_entry.go of the component Maintenance Entry Repository. The manipulation of the argument ID leads to improper privilege management.
This vulnerability is uniquely identified as CVE-2026-48975. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.VulDB Recent EntriesRead More