Access Control Flaw in OpenRemote IoT Platform by OpenRemote
CVE-2026-49439
4.3MEDIUM
What is CVE-2026-49439?
OpenRemote, an open-source internet-of-things platform, has a notable access control vulnerability in its predicted datapoint write endpoint. Users with only basic read:assets permissions can maliciously write predicted datapoints, compromising the integrity of the data within the system. This issue has been resolved in version 1.24.1, which restricts the write capability to users with appropriate permissions, enhancing security and data reliability.
Affected Version(s)
openremote < 1.24.1
