Vulnary
← back to the feed
Critical· 9.3

CVE-2026-64824

Home Assistant Core versions before 2026.7.0 have a path traversal flaw in the backup‑restore feature. By supplying a specially crafted tar file, an attacker can write files to any absolute location on the host system. The flaw is especially dangerous because the official Docker image runs Home Assistant as root, allowing the attacker to overwrite critical files such as sitecustomize.py or custom component directories.

publishedJul 21, 2026
last modifiedJul 21, 2026
sourcesNVD
severity · cvss
9.3
critical · how bad it is
exploitation · epss
<1%
44th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Aug 20, 2026

An official fix is available, so this entry is kept for 30 days and then removed automatically.

01

Who is affected

Home Assistant Core prior to version 2026.7.0, particularly when run from the official Docker image that executes the process as root.

02

Real-world impact

An attacker can place arbitrary files on the host filesystem, including Python modules that are automatically imported. This can lead to remote code execution, allowing the attacker to take full control of the system.

03

Why this severity

The CVSS score of 9.3 reflects the vulnerability’s high exploitability (remote, low effort), the ability to gain high privileges (root), and the severe impact on confidentiality, integrity, and availability. The flaw permits arbitrary file writes that can compromise the entire host.

04

What to do about it

no official fix yet

No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.

No fix documented in sources

05

Timeline

  1. Jul 21, 2026 · 11d ago
    Published
    Disclosed and added to the National Vulnerability Database.
  2. Jul 21, 2026 · 11d ago
    Official fix available
    A vendor patch or mitigation now exists — see the remediation steps above.
06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Attack requirementsNone
Privileges requiredHigh
User interactionActive
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →