Should I use Hubitat?
Local, Reliable, Fast and Private Home Automation - hubitat.com
Depends. Buy if you're a tinkerer with Zigbee/Z-Wave devices who wants fast local automations and accepts a learning curve. Skip it if you want plug-and-play simplicity, a real burglar alarm, or free remote access.
Confidence
Medium. Based on ~25 public sources: vendor pages, community threads, Reddit reviews, CVE records, and company trackers. Many review snippets were truncated, limiting verbatim quotes.
Ratings
- Value for money
- Ease of use
- Feature depth
- Support quality
- Security posture
Pricing
$129.95+ one-time
Hub hardware (C-7 / C-8 Pro)
ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Hub ProtectPaid subscription
Remote AdminPaid subscription
Best for
- →Tech enthusiasts and tinkerers
- →Privacy-focused, local-first automations
- →Homes with many Zigbee/Z-Wave devices
- →Migrants from Wink, SmartThings, or ISY
Not for
- ×Casual users wanting plug-and-play smart home
- ×Anyone relying on it as a burglar alarm
- ×Buyers of used hubs (registration restrictions reported)
- ×People unwilling to pay for remote access
Gotchas - check before you buy
high
Used hubs reportedly can't be re-registered; buy new or verify transfer policy first
high
CVE-2026-1201 auth bypass affected hubs; keep firmware updated immediately
medium
Remote Admin and Hub Protect are paid subscriptions; 2025 price change caused confusion and billing disputes
medium
Tiny company (<$1M revenue per Owler); users openly question long-term viability
Pros and cons
Pros
- +Runs automations locally: fast, private, no cloud dependency
- +Supports Z-Wave Plus, Zigbee, and Matter devices
- +Active community with guides, case studies, migration help
- +Users report smooth migrations from ISY and SmartThings
- +Matter support built in, per official docs
Cons
- −Auth bypass CVE disclosed Jan 2026 (patched Aug 2025)
- −Hub security hotly debated among its own community
- −Add-on subscription price changes confused and angered users
- −Designed for tech enthusiasts, not plug-and-play beginners
- −Used hubs reportedly blocked from re-registration
Sources & method
Analyzed 9/30/2026 - 13 sources - One known CVE: authorization bypass (CVE-2026-1201) in Hubitat Elevation, disclosed Jan 2026 and fixed in Aug 2025 platform update; community debate over hub security continues.
official x3review x3security x3news x4
- CVE-2026-1201 — Authorization Bypass Through User-Controlled Key, Auth bypass in the Hubitat Elevation platform. Disclosed Jan 2026; fixed in an Aug 2025 platform update. Update hub firmware to current version.
Comments
One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.
No comments yet.