What is CVE-2026-65009?
CVE-2026-65009 is an information disclosure vulnerability in OpenRemote versions prior to 1.26.2. The SyslogResource REST endpoint fails to filter operational logs by realm, allowing attackers with the 'read:rules' role to retrieve logs from all tenants via the GET /api/{realm}/syslog/event endpoint. Immediate update to version 1.26.2 or later is recommended.
Azərbaycanca: CVE-2026-65009 OpenRemote platformunda (1.26.2-dən əvvəlki versiyalar) məlumat sızması zəifliyidir. 'SyslogResource' REST endpoint-i realm əsaslı filtrasiya aparmadığı üçün, 'read:rules' rolu olan hücumçu bütün tenantlara aid əməliyyat loqlarını əldə edə bilər. OpenRemote-i dərhal 1.26.2 və ya daha yeni versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Which REST endpoint in the OpenRemote platform is affected by CVE-2026-65009?
The vulnerability is found in the SyslogResource REST endpoint.
What permission does an attacker need to exploit CVE-2026-65009?
The attacker needs the 'read:rules' role.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.