CVE-2026-27796

MEDIUM

Homarr <1.54.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

Homarr is an open-source dashboard. Prior to version 1.54.0, the integration.all tRPC endpoint in Homarr is exposed as a publicProcedure, allowing unauthenticated users to retrieve a complete list of configured integrations. This metadata includes sensitive information such as internal service URLs, integration names, and service types. This issue has been patched in version 1.54.0.

Scores

CVSS v3 5.3
EPSS 0.0002
EPSS Percentile 6.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-862 CWE-200
Status published
Products (1)
homarr/homarr < 1.54.0
Published Mar 07, 2026
Tracked Since Mar 07, 2026