OpenRemote vulnerabilities
3 CVEs tracked
In our recent reporting, OpenRemote appears primarily in the context of critical vulnerabilities involving authentication bypass, insecure direct object references (IDOR), and lack of realm boundary enforcement. The main events include a vulnerability in the console registration API allowing unauthenticated asset manipulation (CVE-2026-66013) and a critical IDOR in the `AlarmResourceImpl` component due to improper realm validation (CVE-2026-67310). A related vulnerability (CVE-2026-73616) also allows realm administrators to delete notifications across different realms. Defenders should immediately upgrade to version 1.26.2 or later and carefully audit API access controls, specifically the enforcement mechanisms for realm boundaries.
Azərbaycanca: Son hesabatlarımızda OpenRemote, əsasən autentifikasiya bypass, identifikator əsaslı təhlükəsizlik pozuntuları (IDOR) və realm (domen) sərhədlərinin qorunmaması ilə bağlı kritik zəifliklər kontekstində görünür. Əsas hadisələr autentifikasiya olunmamış hücumçulara aktivlərin manipulyasiyasına imkan verən konsol qeydiyyat API-sindəki boşluq (CVE-2026-66013) və `AlarmResourceImpl` komponentində realm yoxlamasının düzgün aparılmaması nəticəsində yaranan kritik IDOR zəifliyini (CVE-2026-67310) əhatə edir. Əlaqəli digər zəiflik (CVE-2026-73616) isə realm administratorlarına digər domenlərə məxsus bildirişləri silməyə imkan verir. Müdafiəçilər dərhal 1.26.2 və daha sonrakı versiyalara yeniləmə etməli, həmçinin API giriş nəzarətlərini, xüsusilə realm sərhədlərinin enforcement mexanizmlərini diqqətlə audit etməlidirlər.
This vendor's CVEs3
This hub is built from skopnix's own reporting on OpenRemote: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.