CRITICAL
9.1 CVE-2026-49994 Published 28 Sept 2026
Bluehood API Authentication Bypass Vulnerability
Worried this affects your website?
Bluehood monitors local bluetooth activity. Prior to version 0.7.1, when auth_enabled is set, only the HTML page handlers enforced session validation.
The /api/* handlers (settings, devices, groups, per-device endpoints including /api/device/{mac}/notes) called no auth check at all. This is an authentication bypass vulnerability. A network attacker reachable on the dashboard port could:
- Read Bluetooth tracking data
- Modify application state, including the heartbeat URL, prune retention, device groups, and per-device notes
- Do so without a session cookie
This issue has been patched in version 0.7.1.
Reference: CVE-2026-49994 on NVD
← Back to Security News