XML External Entity Processing Vulnerability in OpenRemote IoT Platform
CVE-2026-40882
7.6HIGH
What is CVE-2026-40882?
The OpenRemote IoT platform, prior to version 1.22.0, contains an XML external entity (XXE) vulnerability within its Velbus asset import feature. This flaw allows authenticated users to send attacker-controlled XML through the import endpoint without adequate hardening measures in place. Exploitation of this vulnerability may result in server-side file disclosure and unauthorized server-side request forgery (SSRF), potentially exposing sensitive information. Users are advised to upgrade to version 1.22.0 or later to mitigate this risk.
Affected Version(s)
openremote < 1.22.0
