Vulnerability record · CVE-2023-27482 · published 8 March 2023
CVE-2023-27482: Home Assistant Supervisor authentication bypass via API
Home Assistant · Home Assistant
Home Assistant Supervisor 2023.01.1 and older contains an improper authentication flaw (CWE-287) that lets a remote attacker bypass authentication and reach the Supervisor API through Home Assistant. Because the Supervisor controls the host and add-ons, bypassing its authentication is a full compromise of the installation, and the flaw affects all installation types that use the Supervisor.
Description
homeassistant is an open source home automation tool. A remotely exploitable vulnerability bypassing authentication for accessing the Supervisor API through Home Assistant has been discovered. This impacts all Home Assistant installation types that use the Supervisor 2023.01.1 or older. Installation types, like Home Assistant Container (for example Docker), or Home Assistant Core manually in a Python environment, are not affected. The issue has been mitigated and closed in Supervisor version 2023.03.1, which has been rolled out to all affected installations via the auto-update feature of the Supervisor. This rollout has been completed at the time of publication of this advisory. Home Assistant Core 2023.3.0 included mitigation for this vulnerability. Upgrading to at least that version is thus advised. In case one is not able to upgrade the Home Assistant Supervisor or the Home Assistant Core application at this time, it is advised to not expose your Home Assistant instance to the internet.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 10.0 with network reachability, no authentication, scope change and very high EPSS make this an urgent patch-or-isolate case.
What it is
Home Assistant Supervisor 2023.01.1 and older contains an improper authentication flaw (CWE-287) that lets a remote attacker bypass authentication and reach the Supervisor API through Home Assistant. Because the Supervisor controls the host and add-ons, bypassing its authentication is a full compromise of the installation, and the flaw affects all installation types that use the Supervisor.
Impact
An unauthenticated remote attacker gains access to the Supervisor API, which can lead to full control of the Home Assistant host and its managed components, consistent with the CVSS scope change and high confidentiality, integrity and availability ratings.
Attack surface
Reachable over the network (AV:N) with no privileges (PR:N) and no user interaction (UI:N), meaning any internet-exposed Home Assistant instance using the affected Supervisor can be targeted directly. Container and manual Core installations are not affected.
Exploitation
Not listed in CISA KEV and no ransomware association is documented, but EPSS is very high (0.71974, 99.4th percentile), and public writeups and advisories exist, indicating meaningful real-world exploitation risk.
What to do
- Upgrade Home Assistant Supervisor to 2023.03.1 or later (auto-update already rolled this out to affected installations).
- Upgrade Home Assistant Core to at least 2023.3.0, which includes mitigation.
- If upgrading is not possible, remove internet exposure of the Home Assistant instance immediately.
- Verify the Supervisor version on every installation and confirm auto-update completed.
- Restrict network access to the Supervisor API to trusted management networks only.
Detection
- Audit Supervisor and Core version strings across all Home Assistant instances to find those below 2023.03.1 / 2023.3.0.
- Review Supervisor API and Home Assistant access logs for unauthenticated or anomalous requests, especially from external IPs.
- Monitor for unexpected add-on installs, configuration changes or host-level commands issued through the Supervisor API.
- Alert on new or unusual inbound connections to Home Assistant/Supervisor ports from the internet.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-27482 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-27482), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.