CVE Explorer
CVE-2026-54317
Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.6.0, the Konnected integration registers an HTTP endpoint, KonnectedView (homeassistant/components/konnected/__init__.py), that is marked as not requiring authentication (requires_auth = False). A comment next to that line says auth is instead handled "via the access token from configuration." That promise is only half true. Write requests (POST and PUT) are handled by update_sensor(),
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-200","description":"CWE-200: Exposure of Sensitive Information to an Unauthorized Actor","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:2b0a60034dee177fdc11e0b3f54534fe618a3c832d1debc114afc1e9cfe61061 · sha256:abeed6cec2be0450… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-306","description":"CWE-306: Missing Authentication for Critical Function","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:2b0a60034dee177fdc11e0b3f54534fe618a3c832d1debc114afc1e9cfe61061 · sha256:abeed6cec2be0450… · /containers/cna/problemTypes/1/descriptions/0
Affected products and versions
1 source assertion{"product":"core","vendor":"home-assistant","versions":[{"status":"affected","version":"< 2026.6.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:2b0a60034dee177fdc11e0b3f54534fe618a3c832d1debc114afc1e9cfe61061 · sha256:abeed6cec2be0450… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"ADJACENT_NETWORK","availabilityImpact":"LOW","baseScore":7.6,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:2b0a60034dee177fdc11e0b3f54534fe618a3c832d1debc114afc1e9cfe61061 · sha256:abeed6cec2be0450… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
2 source assertions{"cweId":"CWE-200","description":"CWE-200: Exposure of Sensitive Information to an Unauthorized Actor","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:2b0a60034dee177fdc11e0b3f54534fe618a3c832d1debc114afc1e9cfe61061 · sha256:abeed6cec2be0450… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-306","description":"CWE-306: Missing Authentication for Critical Function","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:2b0a60034dee177fdc11e0b3f54534fe618a3c832d1debc114afc1e9cfe61061 · sha256:abeed6cec2be0450… · /containers/cna/problemTypes/1/descriptions/0
Source references
2 source assertions{"tags":["exploit"],"url":"https://github.com/home-assistant/core/security/advisories/GHSA-x84v-g949-293w"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:2b0a60034dee177fdc11e0b3f54534fe618a3c832d1debc114afc1e9cfe61061 · sha256:abeed6cec2be0450… · /containers/adp/0/references/0
{"name":"https://github.com/home-assistant/core/security/advisories/GHSA-x84v-g949-293w","tags":["x_refsource_CONFIRM"],"url":"https://github.com/home-assistant/core/security/advisories/GHSA-x84v-g949-293w"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:2b0a60034dee177fdc11e0b3f54534fe618a3c832d1debc114afc1e9cfe61061 · sha256:abeed6cec2be0450… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.