CVE-2026-34205

Home Assistant is open source home automation software that puts local control and privacy first. Home Assistant apps (formerly add-ons) configured with host network mode expose unauthenticated endpoints bound to the internal Docker bridge interface to the local network. On Linux, this configuration does not restrict access to the app as intended, allowing any device on the same network to reach these endpoints without authentication. Home Assistant Supervisor 2026.03.02 addresses the issue.
Configurations

No configuration.

History

No history.

Information

Published : 2026-03-27 20:16

Updated : 2026-03-30 13:26


NVD link : CVE-2026-34205

Mitre link : CVE-2026-34205

CVE.ORG link : CVE-2026-34205


JSON object : View

Products Affected

No product.

CWE
CWE-923

Improper Restriction of Communication Channel to Intended Endpoints