External risk intelligence

Homer Telecom Observability Default Admin Credentials Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-62252

Homer is a telecom observability platform. Such monitoring and management interfaces for network-facing services are commonly deployed as web-based applications intended to be accessible to administrators, often via a web interface that can be exposed to the internet or reachable across internal network segments, making the login endpoint a common target for external network access.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory details a critical vulnerability in Homer, an open-source telecom observability software, specifically affecting deployments using internal authentication before version 11.0.283. The issue stems from an automatically created default administrative account with a predictable password during initial setup, which lacks a mandatory change upon first login. This could allow unauthorized individuals direct administrative access to the system if they can reach the login endpoint.

  • Default admin credentials grant full system access.
  • Protects telecom observability systems from unauthorized control.
  • Verify Homer deployment relevance and exposure.

Attack Path

How an attacker could exploit the issue

An attacker can gain full administrative control of a Homer deployment by accessing its login endpoint. This is possible because newly deployed instances of Homer, prior to a specific version, automatically create an administrative account with a default, hardcoded password. Once the attacker reaches the login page, they can use these credentials to access the system.

  • Unauthenticated network access to login endpoint.
  • Default `admin` account with `sipcapture` password.
  • Full administrative access to the system.

Live Threat

Current exploitation, exposure, and threat context

When Homer is deployed with internal authentication and prior to version 11.0.283, an `admin` account with a default password exists. An attacker reaching the login endpoint could gain full administrative access, potentially affecting service behavior and sensitive information.

  • Admin access to Homer is at risk.
  • Attackers can reach the login endpoint.
  • Compromise of observability data is possible.

Operational Fix

Recommended remediation, mitigation, and detection steps

For Homer deployments using internal authentication, platform or infrastructure teams should take the lead in addressing this vulnerability, as they typically manage observability tools. The first critical step is to identify all Homer instances, confirm their network accessibility and business criticality, and then locate the specific owner for each instance to plan remediation.

  • Platform or infrastructure teams own resolution.
  • Verify Homer instance reachability and criticality.
  • Plan and execute updates during maintenance windows.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Homer and why is it used?

Homer is an open-source platform designed for telecom observability. Technical teams use it to capture, store, and analyze SIP and VoIP traffic data, providing deep visibility into network performance and call quality across complex communication infrastructures.

What does CWE-798 mean for CVE-2026-62252?

CWE-798 refers to the use of hard-coded credentials. In this vulnerability, it means Homer automatically generates an administrative account with a known, predictable password during setup. Because the system does not force an immediate password change, the account remains insecurely configured by default.

How is this Homer vulnerability triggered?

An attacker triggers this by navigating to the Homer login endpoint and providing the default admin credentials. This vulnerability does not apply to systems that have already updated to version 11.0.283 or to deployments that are not using the internal authentication mechanism.

Is my Homer instance at risk?

If you run an affected version using internal authentication, your instance is at risk if the login endpoint is reachable over a network. According to Halo Surface Signal, because Homer is a management interface, these login pages are often accessible via internal segments or the internet, increasing the likelihood of unauthorized discovery.

Do I need to do something if I run Homer?

Yes. First, inventory your Homer instances to identify which versions are deployed. If you are running a version prior to 11.0.283 with internal authentication, update to 11.0.283 or later immediately. Ensure you change all default credentials to strong, unique passwords as part of your hardening process.

References