← Vulnerability feed

Vulnerability record · CVE-2023-27482 · published 8 March 2023

CVE-2023-27482: Home Assistant Supervisor authentication bypass via API

Home Assistant · Home Assistant

Home Assistant Supervisor 2023.01.1 and older contains an improper authentication flaw (CWE-287) that lets a remote attacker bypass authentication and reach the Supervisor API through Home Assistant. Because the Supervisor controls the host and add-ons, bypassing its authentication is a full compromise of the installation, and the flaw affects all installation types that use the Supervisor.

10.0 CVSS 3.1 Critical EPSS 72% · top 0.6% CWE-287 · Improper authentication
10.0CVSS 3.1 base score
72%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

homeassistant is an open source home automation tool. A remotely exploitable vulnerability bypassing authentication for accessing the Supervisor API through Home Assistant has been discovered. This impacts all Home Assistant installation types that use the Supervisor 2023.01.1 or older. Installation types, like Home Assistant Container (for example Docker), or Home Assistant Core manually in a Python environment, are not affected. The issue has been mitigated and closed in Supervisor version 2023.03.1, which has been rolled out to all affected installations via the auto-update feature of the Supervisor. This rollout has been completed at the time of publication of this advisory. Home Assistant Core 2023.3.0 included mitigation for this vulnerability. Upgrading to at least that version is thus advised. In case one is not able to upgrade the Home Assistant Supervisor or the Home Assistant Core application at this time, it is advised to not expose your Home Assistant instance to the internet.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 10.0 with network reachability, no authentication, scope change and very high EPSS make this an urgent patch-or-isolate case.

What it is

Home Assistant Supervisor 2023.01.1 and older contains an improper authentication flaw (CWE-287) that lets a remote attacker bypass authentication and reach the Supervisor API through Home Assistant. Because the Supervisor controls the host and add-ons, bypassing its authentication is a full compromise of the installation, and the flaw affects all installation types that use the Supervisor.

Impact

An unauthenticated remote attacker gains access to the Supervisor API, which can lead to full control of the Home Assistant host and its managed components, consistent with the CVSS scope change and high confidentiality, integrity and availability ratings.

Attack surface

Reachable over the network (AV:N) with no privileges (PR:N) and no user interaction (UI:N), meaning any internet-exposed Home Assistant instance using the affected Supervisor can be targeted directly. Container and manual Core installations are not affected.

Exploitation

Not listed in CISA KEV and no ransomware association is documented, but EPSS is very high (0.71974, 99.4th percentile), and public writeups and advisories exist, indicating meaningful real-world exploitation risk.

What to do

  • Upgrade Home Assistant Supervisor to 2023.03.1 or later (auto-update already rolled this out to affected installations).
  • Upgrade Home Assistant Core to at least 2023.3.0, which includes mitigation.
  • If upgrading is not possible, remove internet exposure of the Home Assistant instance immediately.
  • Verify the Supervisor version on every installation and confirm auto-update completed.
  • Restrict network access to the Supervisor API to trusted management networks only.

Detection

  • Audit Supervisor and Core version strings across all Home Assistant instances to find those below 2023.03.1 / 2023.3.0.
  • Review Supervisor API and Home Assistant access logs for unauthenticated or anomalous requests, especially from external IPs.
  • Monitor for unexpected add-on installs, configuration changes or host-level commands issued through the Supervisor API.
  • Alert on new or unusual inbound connections to Home Assistant/Supervisor ports from the internet.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-27482 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.6CVE-2023-41895Home-assistant cross-site scripting vulnerabilityHome assistant is an open source home automation. The Home Assistant login page allows users to use their local Home Assistant credentials and log in…EPSS 0.67%9.6CVE-2023-41897Home-assistant clickjacking vulnerabilityHome assistant is an open source home automation. Home Assistant server does not set any HTTP security headers, including the X-Frame-Options header,…EPSS 0.95%9.0CVE-2023-41896Home-assistant insufficient verification of data authenticity vulnerabilityHome assistant is an open source home automation. Whilst auditing the frontend code to identify hidden parameters, Cure53 detected `auth_callback=1`,…EPSS 0.27%7.6CVE-2026-54317Home-assistant information exposure vulnerabilityHome Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.6.0, the Konnected integration regist…EPSS 0.31%7.5CVE-2020-36517Home-assistant observable discrepancy vulnerabilityAn information leak in Nabu Casa Home Assistant Operating System and Home Assistant Supervised 2022.03 allows a DNS operator to gain knowledge about …EPSS 2.9%7.5CVE-2018-21019Home-assistant information exposure vulnerabilityHome Assistant before 0.67.0 was vulnerable to an information disclosure that allowed an unauthenticated attacker to read the application's error log…EPSS 1.7%7.3CVE-2026-33045Home-assistant cross-site scripting vulnerabilityHome Assistant is open source home automation software that puts local control and privacy first. Starting in version 2025.02 and prior to version 20…EPSS 0.25%7.3CVE-2026-33044Home-assistant cross-site scripting vulnerabilityHome Assistant is open source home automation software that puts local control and privacy first. Starting in version 2020.02 and prior to version 20…EPSS 0.28%

Source: NIST National Vulnerability Database (record CVE-2023-27482), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.