CVE-2026-49994 Details
Description
Bluehood monitors local bluetooth activity. Prior to version 0.7.1, when auth_enabled is set in Bluehood, only the HTML page handlers enforced session validation. The /api/* handlers (settings, devices, groups, per-device endpoints including /api/device/{mac}/notes) called no auth check at all. A network attacker reachable on the dashboard port could read Bluetooth tracking data and modify application state — including the heartbeat URL, prune retention, device groups, and per-device notes — without a session cookie. This issue has been patched in version 0.7.1.
A missing authentication vulnerability has been identified in Bluehood, a Bluetooth activity monitoring application, in versions prior to 0.7.1. When the 'auth_enabled' feature is activated, the application fails to enforce session validation on its API routes, allowing network attackers to access Bluetooth tracking data and alter application settings without a session cookie. This vulnerability is particularly concerning as it enables unauthorized modifications to device groups, per-device notes, and other application states. The issue has been patched in version 0.7.1.
Users should upgrade to Bluehood version 0.7.1, which addresses this vulnerability by implementing a default-deny authentication middleware that requires a valid session for all routes except a specified allowlist of authentication endpoints. For those unable to upgrade immediately, it is recommended to use a reverse proxy that requires authentication or to restrict access to the dashboard port.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 28, 2026CISA-ADP
Assessed Sep 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/dannymcc/bluehood/commit/401479938c0deb1f6f6847d442f98a2d03efca68 | [email protected] | Source CodeVendor |
| https://github.com/dannymcc/bluehood/releases/tag/v0.7.1 | [email protected] | Release NotesVendor |
| https://github.com/dannymcc/bluehood/security/advisories/GHSA-qj2j-wcg3-74jw | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Bluehood | <= 0.7.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 28, 2026 | CVE Modified | CISA-ADP |
| Sep 28, 2026 | New CVE Received | [email protected] |
Volerion