Openremote

Openremote

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS -
  • Veröffentlicht 23.06.2026 21:17:03
  • Zuletzt bearbeitet 23.06.2026 22:16:32

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it's a duplicate of CVE-2026-56784.

  • EPSS 0.26%
  • Veröffentlicht 23.06.2026 12:13:07
  • Zuletzt bearbeitet 23.06.2026 22:16:32

OpenRemote before 1.25.0 contains an insecure direct object reference (IDOR) vulnerability in the bulk alarm deletion endpoint that allows authenticated users to permanently delete alarms belonging to other tenants by supplying arbitrary alarm IDs. T...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 22.04.2026 20:33:23
  • Zuletzt bearbeitet 24.04.2026 13:24:32

OpenRemote is an open-source internet-of-things platform. Prior to version 1.22.0, the Velbus asset import path parses attacker-controlled XML without explicit XXE hardening. An authenticated user who can call the import endpoint may trigger XML exte...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 22.04.2026 20:31:29
  • Zuletzt bearbeitet 24.04.2026 13:10:21

OpenRemote is an open-source internet-of-things platform. Prior to version 1.22.1, a user who has `write:admin` in one Keycloak realm can call the Manager API to update Keycloak realm roles for users in another realm, including `master`. The handler ...

Exploit
  • EPSS 0.92%
  • Veröffentlicht 14.04.2026 23:21:22
  • Zuletzt bearbeitet 23.04.2026 17:34:49

OpenRemote is an open-source IoT platform. Versions 1.21.0 and below contain two interrelated expression injection vulnerabilities in the rules engine that allow arbitrary code execution on the server. The JavaScript rules engine executes user-suppli...

Exploit
  • EPSS 1.7%
  • Veröffentlicht 06.09.2022 18:15:15
  • Zuletzt bearbeitet 12.06.2025 14:15:29

An issue was discovered in OpenRemote through 1.0.4 allows attackers to execute arbitrary code via a crafted Groovy rule.