CVE-2026-55844Disclosure

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2025.5.0, The iOS companion app ignores the SSID allowlist for internal networks. The app uses SSID to detect when to use the internal URL, but whenever the app cannot find any other URL to be used, it fallbacks to the internal URL as well, which can expose user's token when connected to a not secure network. This vulnerability is fixed in 2025.5.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-319

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-06-29); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-06-29: 2Mentions · 2026-06-30: 1Patch / Workaround · 2026-06-29: 1Patch / Workaround · 2026-06-30: 1Technical Details · 2026-06-29: 2Technical Details · 2026-06-30: 106-2906-30
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-06-292
Disclosure2
2026-06-301
Patch1
Full discourse3 posts
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH severity CVE-2026-55844 (CVSS 7.5): Home Assistant iOS app bypasses SSID allowlist, exposing user tokens on untrusted networks. Update to v2025.5.0 immediately. #CVE #Vulnerability #PatchNow https://t.co/nlSLnmEqtx

    Post summary

    The tweet announces a high‑severity CVE–2026‑55844 affecting Home Assistant iOS, explains the technical flaw, and urges users to patch to v2025.5.0.

    0000062
    55 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-55844 Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2025.5.0, The iOS companion app ignores the SSID allowlist … https://www.cve.org/CVERecord?id=CVE-2026-55844 ----- Traducción: CVE-2026-55844 Hom… http://infoflow.cloud`

    Post summary

    The post references CVE-2026‑55844, noting that the iOS companion app prior to version 2025.5.0 ignores the SSID allowlist.

    0000041
    89 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-55844 Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2025.5.0, The iOS companion app ignores the SSID allowlist … https://www.cve.org/CVERecord?id=CVE-2026-55844

    Post summary

    The text discloses a Slack issue where the Home Assistant iOS app ignores the SSID allowlist, with the 2025.5.0 update likely providing a fix.

    00000710
    57.7K followersView on X

Explore more