XML External Entity Processing Vulnerability in OpenRemote IoT Platform
CVE-2026-40882

7.6HIGH

Key Information:

Vendor

Openremote

Vendor
CVE Published:
22 April 2026

What is CVE-2026-40882?

The OpenRemote IoT platform, prior to version 1.22.0, contains an XML external entity (XXE) vulnerability within its Velbus asset import feature. This flaw allows authenticated users to send attacker-controlled XML through the import endpoint without adequate hardening measures in place. Exploitation of this vulnerability may result in server-side file disclosure and unauthorized server-side request forgery (SSRF), potentially exposing sensitive information. Users are advised to upgrade to version 1.22.0 or later to mitigate this risk.

Affected Version(s)

openremote < 1.22.0

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.