CRITICAL 9.1 CVE-2026-49994 Published 28 Sept 2026

Bluehood API Authentication Bypass Vulnerability

Worried this affects your website?

Bluehood monitors local bluetooth activity. Prior to version 0.7.1, when auth_enabled is set, only the HTML page handlers enforced session validation.

The /api/* handlers (settings, devices, groups, per-device endpoints including /api/device/{mac}/notes) called no auth check at all. This is an authentication bypass vulnerability. A network attacker reachable on the dashboard port could:

  • Read Bluetooth tracking data
  • Modify application state, including the heartbeat URL, prune retention, device groups, and per-device notes
  • Do so without a session cookie

This issue has been patched in version 0.7.1.

Reference: CVE-2026-49994 on NVD

← Back to Security News