Insecure Direct Object Reference Vulnerability in OpenRemote Manager by OpenRemote
CVE-2026-56784
7.2HIGH
What is CVE-2026-56784?
OpenRemote Manager prior to version 1.24.2 is susceptible to an insecure direct object reference vulnerability. The flaw arises in the removeAlarms() method, where authenticated users can exploit the system by submitting arbitrary alarm IDs, thereby enabling deletion of alarms that do not belong to their own tenant. This vulnerability facilitates unauthorized bulk deletion of critical alerts, leading to a potential loss of safety and security measures within affected environments.
Affected Version(s)
openremote 0 < 1.24.2
openremote 1.24.2
