Openremote

Openremote

11 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.18%
  • Veröffentlicht 13.08.2026 11:28:18
  • Zuletzt bearbeitet 13.08.2026 15:20:20

OpenRemote notification deletion endpoints fail to enforce realm boundaries, allowing any realm administrator to delete notifications belonging to other realms. Attackers with write:admin role in one realm can send DELETE requests to remove notificat...

  • EPSS 0.18%
  • Veröffentlicht 01.08.2026 12:22:17
  • Zuletzt bearbeitet 03.08.2026 17:16:40

OpenRemote (org.openremote:openremote) versions <= 1.26.2 contain an insecure direct object reference vulnerability in the setAssetLinks endpoint of AlarmResourceImpl. The realm access check validates only a single realm obtained via realms.stream()....

  • EPSS 0.39%
  • Veröffentlicht 25.07.2026 10:45:56
  • Zuletzt bearbeitet 30.07.2026 20:11:09

OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that allows unauthenticated attackers to update existing console assets by supplying a known asset identifier. Attackers can overwrite push notif...

  • EPSS 0.18%
  • Veröffentlicht 21.07.2026 11:39:57
  • Zuletzt bearbeitet 23.07.2026 15:24:59

OpenRemote versions before 1.26.2 contain an information disclosure vulnerability in the SyslogResource REST endpoint that fails to filter operational logs by realm. Attackers with the read:rules role can access the GET /api/{realm}/syslog/event endp...

Exploit
  • EPSS 0.33%
  • Veröffentlicht 17.07.2026 00:07:12
  • Zuletzt bearbeitet 30.07.2026 14:26:39

OpenRemote before 1.26.0 contain an authenticated SQL injection vulnerability in the datapoint crosstab export endpoint that constructs PostgreSQL queries by concatenating asset display names into raw SQL. An authenticated attacker with asset creatio...

  • EPSS -
  • Veröffentlicht 23.06.2026 21:17:03
  • Zuletzt bearbeitet 23.06.2026 22:16:32

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it's a duplicate of CVE-2026-56784.

  • EPSS 0.26%
  • Veröffentlicht 23.06.2026 12:13:07
  • Zuletzt bearbeitet 14.07.2026 22:17:22

OpenRemote before 1.25.0 contains an insecure direct object reference (IDOR) vulnerability in the bulk alarm deletion endpoint that allows authenticated users to permanently delete alarms belonging to other tenants by supplying arbitrary alarm IDs. T...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 22.04.2026 20:33:23
  • Zuletzt bearbeitet 24.04.2026 13:24:32

OpenRemote is an open-source internet-of-things platform. Prior to version 1.22.0, the Velbus asset import path parses attacker-controlled XML without explicit XXE hardening. An authenticated user who can call the import endpoint may trigger XML exte...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 22.04.2026 20:31:29
  • Zuletzt bearbeitet 24.04.2026 13:10:21

OpenRemote is an open-source internet-of-things platform. Prior to version 1.22.1, a user who has `write:admin` in one Keycloak realm can call the Manager API to update Keycloak realm roles for users in another realm, including `master`. The handler ...

Exploit
  • EPSS 0.92%
  • Veröffentlicht 14.04.2026 23:21:22
  • Zuletzt bearbeitet 23.04.2026 17:34:49

OpenRemote is an open-source IoT platform. Versions 1.21.0 and below contain two interrelated expression injection vulnerabilities in the rules engine that allow arbitrary code execution on the server. The JavaScript rules engine executes user-suppli...