Homarr, an open-source dashboard application, contains a race condition vulnerability in its user registration endpoint (CVE-2026-32602) that allows attackers to bypass single-use invite token restrictions and create multiple user accounts. The vulnerability stems from three non-atomic database operations (CHECK, CREATE, DELETE) that are performed sequentially without transactional protection, enabling concurrent requests to circumvent validation controls. This flaw affects all versions prior to 1.57.0. The vulnerability carries a CVSS score of 4.2 (Medium severity) and requires network access with low privilege and moderate attack complexity. Exploitation results in limited confidentiality and integrity impacts, as attackers can create unauthorized accounts but cannot impact system availability or escalate privileges significantly. The EPSS score of 0.00029 indicates minimal exploitation probability relative to other vulnerabilities. There is currently no evidence of active exploitation in the wild, no publicly available proof-of-concept code noted in the KEV catalog, and the vulnerability maintains an inactive status on vulnerability hotlists. Patching to version 1.57.0 or later is recommended for all Homarr installations to resolve this issue and prevent unauthorized account creation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.57.0CPE matchmatch criteria | cpe:2.3:a:homarr:homarr:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.