Privilege Escalation Vulnerability in OpenRemote IoT Platform
CVE-2026-41166
7HIGH
What is CVE-2026-41166?
OpenRemote, an open-source IoT platform, contains a vulnerability that allows users with 'write:admin' capability in one Keycloak realm to manipulate realm roles for other users across different realms, including the master realm. This occurs due to inadequate checks on the caller's permissions when accessing the Manager API. An attacker controlling a user in the master realm could exploit this flaw to escalate their privileges and gain unauthorized administrative access. The issue has been resolved in version 1.22.1, which ensures proper verification of user permissions when handling realm-specific actions.
Affected Version(s)
openremote < 1.22.1
