Homarr is an open-source dashboard. Prior to version 1.54.0, the integration.all tRPC endpoint in Homarr is exposed as a publicProcedure, allowing unauthenticated users to retrieve a complete list of configured integrations. This metadata includes sensitive information such as internal service URLs, integration names, and service types. This issue has been patched in version 1.54.0.
Metrics
Affected Vendors & Products
References
History
Mon, 09 Mar 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 09 Mar 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Homarr-labs
Homarr-labs homarr |
|
| Vendors & Products |
Homarr-labs
Homarr-labs homarr |
Sat, 07 Mar 2026 06:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Homarr is an open-source dashboard. Prior to version 1.54.0, the integration.all tRPC endpoint in Homarr is exposed as a publicProcedure, allowing unauthenticated users to retrieve a complete list of configured integrations. This metadata includes sensitive information such as internal service URLs, integration names, and service types. This issue has been patched in version 1.54.0. | |
| Title | Homarr: Unauthenticated Information Disclosure (Integration Metadata Leak) | |
| Weaknesses | CWE-200 CWE-862 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-03-07T05:54:48.829Z
Updated: 2026-03-09T20:44:25.718Z
Reserved: 2026-02-24T02:31:33.265Z
Link: CVE-2026-27796
Updated: 2026-03-09T20:41:57.239Z
Status : Awaiting Analysis
Published: 2026-03-07T06:16:09.663
Modified: 2026-03-09T13:35:34.633
Link: CVE-2026-27796
No data.
ReportizFlow