Generated remediation guidance and an executive summary. No account required.
HomeBox is a home inventory and organization system. Prior to 0.24.0-rc.1, the notifier functionality allows authenticated users to specify arbitrary URLs to which the application sends HTTP POST requests. No validation or restriction is applied to the supplied host, IP address, or port. Although the application does not return the response body from the target service, its UI behavior differs depending on the network state of the destination. This creates a behavioral side-channel that enables internal service enumeration. This vulnerability is fixed in 0.24.0-rc.1.
Cite this page
CVE-2026-27600. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2026-27600
Use CWE-918, Sysadminsmedia vendor hub and Homebox product page to widen CVE-2026-27600 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-40196, CVE-2026-27981 and CVE-2026-26272 for nearby disclosures in the same product family.