Disclosure summary
### Summary On every fresh Homer deployment using internal authentication, the bootstrap process automatically creates an `admin` account with the password `sipcapture` (stored as a legacy SHA-256 hex hash). There is no first-login forced-change mechanism. Any attacker who reaches the login endpoint immediately gains full administrative access. ### Details **`config/config.go` lines 858-861:** ```go // DefaultInternalAuthPasswordHash is the SHA-256 hex digest of the default // bootstrap password (cleartext: sipcapture). const DefaultInternalAuthPasswordHash = "883ffc1f37fd0fe542b0fb9740035c4383e7d976c411161d24e62edace280f90" ``` **`coordinator/services/auth_bootstrap.go` lines 20-71:** `EnsureBootstrapAdminUser()` runs at startup. If no admin user exists, it inserts a row with `username=admin`, `password_hash=DefaultInternalAuthPasswordHash`. No `force_change`, no `first_login` flag, no expiry is set. **`coordinator/services/auth_bootstrap_test.go` line 114** confirms the plaintext: ```go u, err := svc.Authenticate(ctx, "admin", "sipcapture") ``` **`passwordhash/password.go` lines 36-45:** Legacy SHA-256 hex hashes are accepted via `legacySHA256HexEqual`, so the default credential
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-6xp5-7rcx-xfgx
Open original source · Updated Oct 07, 2026
Homer: Hardcoded Default Admin Password 'sipcapture' With No Forced Change on First Login
Source severity: CRITICAL / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| go | github.com/sipcapture/homer-app | < 0.0.0-20260625091610-b2e942031ff8 | 0.0.0-20260625091610-b2e942031ff8 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-10-07T12:12:02-04:00
MODIFIED 2026-10-07T12:12:03-04:00
INGESTED 2026-10-08T12:05:11-04:00