HIGH 8.8 GitHub

CVE-2026-59177

ESPHome Device Builder Dashboard: Unauthenticated dashboard access via the HA add-on ingress site bound to all interfaces

## Summary On the Home Assistant add-on, the dashboard serves a trusted ingress site that skips authentication because the supervisor authenticates the request upstream. That site was binding `0.0.0.0`. The add-on runs in host network mode for mDNS, so binding all interfaces also bound the host's LAN interface, and any device on the local network could reach `http://<ha-ip>:<ingress_port>/` and get the full dashboard with no credentials. ## Details The HA add-on ingress site is intentionally

Affected Products

References

Published: 2026-09-09 · Source: GitHub · Feed updated: 2026-09-11
This high severity vulnerability with a CVSS score of 8.8 was published on 2026-09-09 via GitHub. Affected: pip/esphome-device-builder < 1.0.10.
vulnfeed aggregates 13138 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.