CVE-2026-55844 Details
Description
Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2025.5.0, The iOS companion app ignores the SSID allowlist for internal networks. The app uses SSID to detect when to use the internal URL, but whenever the app cannot find any other URL to be used, it fallbacks to the internal URL as well, which can expose user's token when connected to a not secure network. This vulnerability is fixed in 2025.5.0.
A vulnerability exists in the Home Assistant iOS companion app version 2023.471, where the app disregards the SSID allowlist for internal networks. This flaw can lead to the exposure of the user's authentication token when connected to an unsecured network. The issue arises because the app uses SSID to determine when to access the internal URL. If no other URL is available, it defaults to the internal URL, potentially leaking the token over insecure connections. The vulnerability has been addressed in version 2025.5.0.
Users can update to the Home Assistant iOS companion app version 2025.5.0 or later, which enforces the SSID allowlist requirement. The app now offers a connection security level choice, allowing users to select 'Most secure' to ensure compliance with the SSID allowlist or 'Less secure' to bypass this requirement.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 29, 2026CISA-ADP
Assessed Jun 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/home-assistant/core/security/advisories/GHSA-cm5v-547m-qh5h | CISA-ADP | AdvisoryExploitRemedyVendor |
| https://github.com/home-assistant/core/security/advisories/GHSA-cm5v-547m-qh5h | [email protected] | AdvisoryExploitRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-319 | Cleartext Transmission of Sensitive Information | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Home Assistant | All versions |
CPE
Remediation
| |
| Home Assistant Companion | 2023.471 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 30, 2026 | CVE Modified | CISA-ADP |
| Jun 29, 2026 | New CVE Received | [email protected] |
Volerion