Description
Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio exposed administrator-intended backend API actions to any authenticated Home Assistant user because the backend did not consistently enforce the panel's admin-only authorization boundary. Affected surfaces included the backend API, upload API, stream routes, terminal WebSocket, Blueprint Studio WebSocket subscriptions, call_service, render_template, global_replace, file and stream access paths, upload handling, and terminal helpers. A non-admin user could invoke arbitrary Home Assistant services, expose Home Assistant state through templates, modify configuration files, access streamed or downloaded configuration content, upload files, or reach terminal-related helpers. These actions could compromise the confidentiality, integrity, and availability of the Home Assistant installation. This issue is fixed in version 2.5.2.
Published: 2026-08-18
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Blueprint Studio allows any authenticated Home Assistant user who is not an administrator to access a range of backend API actions that were intended only for administrators. This flaw can be exploited to invoke arbitrary Home Assistant services, expose sensitive state data through templates, modify configuration files, and perform file or stream operations. The potential consequence is full compromise of confidentiality, integrity, and availability for the affected Home Assistant installation.

Affected Systems

Blueprint Studio, a VS Code‑like editor for Home Assistant configuration, is affected. The issue exists in all releases prior to version 2.5.2. The problem is resolved in 2.5.2 and later.

Risk and Exploitability

The CVSS score of 8.7 indicates a high‑severity risk. Exploitation requires the attacker to be a legitimate, non‑admin user of the system, which is a realistic scenario for compromised or stolen credentials. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. Given the explicit authorization bypass, the attack vector is through authenticated channels where the attacker can bypass privilege checks to perform unauthorized administrative actions.

Generated by OpenCVE AI on August 21, 2026 at 16:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Blueprint Studio to version 2.5.2 or later to apply the fix.
  • If an upgrade is not immediately possible, restrict non‑admin users from accessing the editor panel or remove them from the list of services that can be called via the API.
  • Verify that your Home Assistant instance enforces role‑based access control and that only administrators can trigger sensitive API calls, upload configuration files, or access stream routes.

Generated by OpenCVE AI on August 21, 2026 at 16:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Ha-china
Ha-china blueprint-studio
Vendors & Products Ha-china
Ha-china blueprint-studio

Wed, 19 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Description Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio exposed administrator-intended backend API actions to any authenticated Home Assistant user because the backend did not consistently enforce the panel's admin-only authorization boundary. Affected surfaces included the backend API, upload API, stream routes, terminal WebSocket, Blueprint Studio WebSocket subscriptions, call_service, render_template, global_replace, file and stream access paths, upload handling, and terminal helpers. A non-admin user could invoke arbitrary Home Assistant services, expose Home Assistant state through templates, modify configuration files, access streamed or downloaded configuration content, upload files, or reach terminal-related helpers. These actions could compromise the confidentiality, integrity, and availability of the Home Assistant installation. This issue is fixed in version 2.5.2.
Title Blueprint Studio API authorization bypass for non-admin Home Assistant users
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Ha-china Blueprint-studio
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-08-19T13:17:06.706Z

Reserved: 2026-06-09T16:31:21.494Z

Link: CVE-2026-53453

cve-icon Vulnrichment

Updated: 2026-08-19T13:17:03.392Z

cve-icon NVD

Status : Received

Published: 2026-08-18T21:16:34.973

Modified: 2026-08-19T14:17:32.637

Link: CVE-2026-53453

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T16:30:06Z

Weaknesses