CVE-2026-48826 | sysadminsmedia Homebox up to 0.25.x Wipe Inventory v1_ctrl_actions.go HandleWipeInventory X-Tenant improper authorization
A vulnerability marked as problematic has been reported in sysadminsmedia Homebox up to 0.25.x. The impacted element is the function HandleWipeInventory of the file backend/app/api/handlers/v1/v1_ctrl_actions.go of the component Wipe Inventory. Performing a manipulation of the argument X-Tenant results in improper authorization.
This vulnerability is known as CVE-2026-48826. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More