AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-66061

HIGH · CVSS 7.1 EPSS 0.11% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-07 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The Home Assistant iOS Companion app is vulnerable to exploitation through tag links (NFC or QR) that are improperly validated, allowing untrusted applications to trigger automations without user consent. This flaw enables unauthorized execution of automations, posing a significant risk to user privacy and security. Users of the Home Assistant iOS app should prioritize updating to version 2026.5.0 to mitigate this high-severity vulnerability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-66061
Severity
HIGH
CVSS
7.1
EPSS
0.11%

Original NVD Description

Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.5.0, the iOS Companion app treats tag links (NFC or QR) delivered through an OS-level routing mechanism such as iOS universal links as if they were physically scanned, without validating the calling app or prompting the user. As a result, any untrusted app on the device can forward an arbitrary tag to Home Assistant, causing it to execute the associated automation as though a legitimate user had scanned an authorized tag. This allows silent, unattended automation execution by untrusted local callers. This issue has been fixed in version 2026.5.0.