What is CVE-2026-73616?
CVE-2026-73616: OpenRemote notification deletion endpoints fail to enforce realm boundaries, allowing any realm administrator to delete notifications belonging to other realms. Attackers with write:admin role in one realm can send DELETE requests to remove notifications from the master realm or other tenants. A security update from OpenRemote developers should be applied to mitigate this vulnerability.
Azərbaycanca: CVE-2026-73616: OpenRemote bildiriş silmə endpoint-lərində realm sərhədləri yoxlanılmır, bu da bir realm administratoruna digər realm-lərin (məsələn, master realm) bildirişlərini silməyə imkan verir. Hücumçu write:admin rolu ilə hədəf realm-lərə DELETE sorğuları göndərə bilər. Bu zəifliyi aradan qaldırmaq üçün OpenRemote tərtibatçıları tərəfindən təhlükəsizlik yeniləməsi tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which privileged role can be used to delete notifications from other realms in CVE-2026-73616?
An attacker with the write:admin role in one realm can delete notifications from other realms, including the master realm.
What should be done to mitigate CVE-2026-73616?
A security update from OpenRemote developers should be applied to mitigate this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.