This release includes 1 security fix for security teams reviewing exposed deployments.
Published 1mo
Productivity & Wikis
✓ No known CVEs patched
This release patches 1 known CVE
Topics
homebox
inventory
self-hosted
Summary
AI summaryFixes CVE-2026-40196 where removed users could still access their default group via API.
Security Fixes
- CVE-2026-40196: Removed users could still access their default group via the API
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About homebox
A continuation of HomeBox the inventory and organization system built for the Home User
Beta — feedback welcome: [email protected]