Incident database
ESPHome Device Builder: Auth env vars rename silently disables dashboard authentication
ESPHome Device Builder's environment variable rename from USERNAME/PASSWORD to ESPHOME_USERNAME/ESPHOME_PASSWORD removed backward compatibility, causing deployments using the legacy names to lose authentication on upgrade and expose the dashboard to unauthenticated access.
Disclosed 14 September 2026 · Record updated 14 September 2026
Impact
Unauthenticated network clients can manage ESPHome devices, including editing configurations and flashing firmware, on affected deployments that relied on legacy USERNAME/PASSWORD environment variables.
Our coverage
VulnerabilitiesAn advisory published on 14 September 2026 says upgraded ESPHome Device Builder instances that used the old USERNAME and PASSWORD variables started up with no authentication at all.
14 Sept 2026
Sources
- github.comhttps://github.com/advisories/GHSA-rrxg-g2pf-6hh4