AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-66060

HIGH · CVSS 7.1 EPSS 0.11% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-07 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The Home Assistant Companion app is vulnerable due to improper handling of tag links, allowing untrusted applications to trigger automations without user consent. This could lead to unauthorized actions being executed silently, posing significant risks to user privacy and security. Users and administrators of Home Assistant should prioritize updating to version 2026.8.1 to mitigate this high-severity vulnerability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-66060
Severity
HIGH
CVSS
7.1
EPSS
0.11%

Original NVD Description

Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.5.3, the Companion app treats tag links (NFC or QR) delivered through an OS-level routing mechanism as if they were physically scanned, without validating the calling app or prompting the user. As a result, any untrusted app on the device can forward an arbitrary tag to Home Assistant, causing it to execute the associated automation as though a legitimate user had scanned an authorized tag. This allows silent, unattended automation execution by untrusted local callers. This issue is fixed in version 2026.8.1.