What is CVE-2026-67310?
A critical IDOR vulnerability has been discovered in OpenRemote. The 'setAssetLinks' endpoint's realm check only validates the first realm from a HashSet, allowing attackers to manipulate multiple realms for unauthorized object access. Organizations using versions <= 1.26.2 should immediately patch to the latest version.
Azərbaycanca: OpenRemote platformasında kritik IDOR zəifliyi aşkar edilib. 'setAssetLinks' endpointində realm yoxlaması yalnız birinci realm-i nəzərə aldığı üçün, təcavüzkar çoxsaylı realm-lə manipulyasiya edərək icazəsiz obyektlərə giriş əldə edə bilər. 1.26.2 və aşağı versiyaları istifadə edən təşkilatlar dərhal son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
Which versions of OpenRemote are affected by CVE-2026-67310?
The vulnerability affects versions 1.26.2 and below. Organizations should immediately patch to the latest version.
How does CVE-2026-67310 enable an IDOR attack?
The 'setAssetLinks' endpoint's realm check only validates the first realm from a HashSet, allowing attackers to manipulate multiple realms to gain unauthorized object access.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.