Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-32602

16
FAUCET Score

Homarr, an open-source dashboard application, contains a race condition vulnerability in its user registration endpoint (CVE-2026-32602) that allows attackers to bypass single-use invite token restrictions and create multiple user accounts. The vulnerability stems from three non-atomic database operations (CHECK, CREATE, DELETE) that are performed sequentially without transactional protection, enabling concurrent requests to circumvent validation controls. This flaw affects all versions prior to 1.57.0. The vulnerability carries a CVSS score of 4.2 (Medium severity) and requires network access with low privilege and moderate attack complexity. Exploitation results in limited confidentiality and integrity impacts, as attackers can create unauthorized accounts but cannot impact system availability or escalate privileges significantly. The EPSS score of 0.00029 indicates minimal exploitation probability relative to other vulnerabilities. There is currently no evidence of active exploitation in the wild, no publicly available proof-of-concept code noted in the KEV catalog, and the vulnerability maintains an inactive status on vulnerability hotlists. Patching to version 1.57.0 or later is recommended for all Homarr installations to resolve this issue and prevent unauthorized account creation.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.57.0CPE matchmatch criteria
cpe:2.3:a:homarr:homarr:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

4.2MEDIUM

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
1.6
Impact Score
2.5
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.11%
Probability of exploitation in next 30 days
EPSS Percentile
1.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0011 is in the 0th percentile among its peer group of 1,425 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

github_advisoryvendor investigatingvia nvd_reference
View patch

References

github.com / homarr-labs/homarr/security/advisories/GHSA-vfw3-53q9-2hp8
Third Party AdvisoryVendor Advisory