Authentication bypass: PIN validation fails to reject incorrect PINs #1859

Closed
opened 2026-04-05 19:42:49 +02:00 by MrUnknownDE · 0 comments
Owner

Originally created by @mallendeo on 1/18/2025

I assigned an access PIN to my HomeAssistant instance, but when entering any PIN code, the system grants access regardless of whether the PIN is correct or not.

This does not happen when using only the password method though.

Image

Enabling PIN makes it insecure.

*Originally created by @mallendeo on 1/18/2025* I assigned an access PIN to my HomeAssistant instance, but when entering any PIN code, the system grants access regardless of whether the PIN is correct or not. This does not happen when using only the password method though. <img width="568" alt="Image" src="https://github.com/user-attachments/assets/1ece650c-fd55-4b15-8542-09b7da5adb55" /> Enabling PIN makes it insecure.
Sign in to join this conversation.
No Label
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github/pangolin#1859