CVE-2026-27600 is an authenticated Server-Side Request Forgery (SSRF) vulnerability affecting HomeBox versions prior to 0.24.0-rc.1, where the notifier functionality allows authenticated users to specify arbitrary URLs for HTTP POST requests without validation. This medium-severity vulnerability (CVSS 5.0) has a low attack complexity and requires low privileges, enabling attackers to perform internal service enumeration via a behavioral side-channel. While it can expose internal network details, there is no impact on integrity or availability. Currently, there is no evidence of active exploitation, nor are there any public exploit codes or significant community discussion regarding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.23.1CPE matchmatch criteria | cpe:2.3:a:sysadminsmedia:homebox:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.