CVE-2026-66060 Details
Description
Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.5.3, the Companion app treats tag links (NFC or QR) delivered through an OS-level routing mechanism as if they were physically scanned, without validating the calling app or prompting the user. As a result, any untrusted app on the device can forward an arbitrary tag to Home Assistant, causing it to execute the associated automation as though a legitimate user had scanned an authorized tag. This allows silent, unattended automation execution by untrusted local callers. This issue is fixed in version 2026.8.1.
A vulnerability in the Home Assistant Companion app for Android allows untrusted applications to trigger automations by sending NFC or QR tag links through an OS-level routing mechanism. This issue affects versions prior to 2026.5.3. The Companion app did not validate the source application or prompt the user, leading to unauthorized automation execution as if a legitimate user had scanned an approved tag.
Users can update to Home Assistant Companion app version 2026.8.1 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 7, 2026CISA-ADP
Assessed Aug 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/home-assistant/core/security/advisories/GHSA-2xqv-hwrf-983f | CISA-ADP | AdvisoryExploitRemedyVendor |
| https://github.com/home-assistant/android/commit/968b49c58e4eba4d06371a3f6e73198ec6c8d4a7 | [email protected] | Source CodeVendor |
| https://github.com/home-assistant/core/security/advisories/GHSA-2xqv-hwrf-983f | [email protected] | AdvisoryExploitRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Home Assistant | < 2026.5.3 (semver) |
CPE
Remediation
| |
| Home Assistant Companion | < 2026.5.3 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 13, 2026 | CVE Modified | CISA-ADP |
| Aug 7, 2026 | New CVE Received | [email protected] |
Volerion