CVE 4.2 MEDIUM

Homarr has a Race Condition in Invite Token Registration (TOCTOU)_CVE-2026-32602

4.2 / 10
MEDIUM
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Description

Homarr is an open-source dashboard. Prior to 1.57.0, the user registration endpoint (/api/trpc/user.register) is vulnerable to a race condition that allows an attacker to create multiple user accounts from a single-use invite token. The registration flow performs three sequential database operations without a transaction: CHECK, CREATE, and DELETE. Because these operations are not atomic, concurrent requests can all pass the validation step (1) before any of them reaches the deletion step (3). This allows multiple accounts to be registered using a single invite token that was intended to be single-use. This vulnerability is fixed in 1.57.0.

Basic Information

ID CVE-2026-32602
Source GitHub_M
Published Apr 6, 2026 at 14:42
Modified Apr 6, 2026 at 15:41

Affected Product

Vendor homarr-labs
Product homarr
Version < 1.57.0
Affected Versions homarr-labs homarr < 1.57.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.