← volver
CVE-2026-32602

Homarr has a Race Condition in Invite Token Registration (TOCTOU)

CVSS 4.2 MEDIUMEPSS 0.1%CWE-367
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 4.2EPSS 0.1%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
06 abr 2026Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Homarr is an open-source dashboard. Prior to 1.57.0, the user registration endpoint (/api/trpc/user.register) is vulnerable to a race condition that allows an attacker to create multiple user accounts from a single-use invite token. The registration flow performs three sequential database operations without a transaction: CHECK, CREATE, and DELETE. Because these operations are not atomic, concurrent requests can all pass the validation step (1) before any of them reaches the deletion step (3). This allows multiple accounts to be registered using a single invite token that was intended to be single-use. This vulnerability is fixed in 1.57.0.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Productos afectados
homarr-labs · homarr

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →