A vulnerability classified as problematic has been found in ESPHome up to 2026.7.0. Affected is the function
WebServer::text_json_ of the file esphome/components/web_server/web_server.cpp of the component web_server. The manipulation leads to missing encryption of sensitive data.
This vulnerability is documented as CVE-2026-71260. The attack can be initiated remotely. There is not any exploit available.