CVE-2026-64825
Home Assistant Core versions before 2026.6.0 have a path‑traversal flaw that lets anyone upload a specially crafted backup file and write files anywhere on the host system. The flaw is triggered during the initial onboarding window and works without authentication.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Home Assistant Core prior to version 2026.6.0, used by home automation users who run the software on their own servers.
Real-world impact
An attacker can create or overwrite any file on the host, including system binaries or configuration files. If the Home Assistant process runs as root, the attacker could gain full control of the machine.
Why this severity
The CVSS score of 9 reflects the combination of no authentication required, the ability to write arbitrary files, and the high impact when the software runs with root privileges. The vector shows that the vulnerability is exploitable from the network, requires low effort, and can lead to high impact on confidentiality, integrity, and availability.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources