boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-64824CRITICAL
home-assistant Home Assistant Core — Home Assistant Core < 2026.7.0 Symlink Path Traversal RCE via backup-restore
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   A   H   H   H    9.3   .0058   45.0     —
AFFECTED
  Product              Versions     Fixed
  Home Assistant Core  unspecified  —
TIMELINE
  Jul 20  Reserved by VulnCheck
  Jul 21  Published (CNA: VulnCheck)
  Jul 27  EXPLOIT PUBLISHED — CVE-2026-64824 (home-assistant Home Assistant Core). Public exploit reference added.
CWE-22 · CNA: VulnCheck · CVSS v4.0 · 5 references · NVD status: Deferred

Description

Home Assistant Core before 2026.7.0 contains a path traversal vulnerability in the backup-restore function that allows attackers to write files to arbitrary absolute filesystem paths by supplying a crafted tar archive with a SYMTYPE entry containing a benign member name paired with an absolute linkname pointing outside the extraction directory. Because the official Docker image runs the Home Assistant process as root and the subsequent regular-file entry is written through the unvalidated symlink, attackers can achieve remote code execution by overwriting auto-imported Python paths such as site-packages/sitecustomize.py or custom component directories.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
July 20, 2026ReservedReserved by VulnCheck
July 21, 2026PublishedPublished (CNA: VulnCheck)
July 27, 2026EXPLOIT PUBLISHEDEXPLOIT PUBLISHED — CVE-2026-64824 (home-assistant Home Assistant Core). Public exploit reference added.

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
home-assistantHome Assistant Core

Weaknesses

CWE-22

References (5)

Related

Authoritative record: CVE-2026-64824 at cve.org

Vendors: home-assistant

Weaknesses: CWE-22

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-64824 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.