Insecure Direct Object Reference Vulnerability in OpenRemote Manager by OpenRemote
CVE-2026-56784

7.2HIGH

Key Information:

Vendor

Openremote

Vendor
CVE Published:
23 June 2026

What is CVE-2026-56784?

OpenRemote Manager prior to version 1.24.2 is susceptible to an insecure direct object reference vulnerability. The flaw arises in the removeAlarms() method, where authenticated users can exploit the system by submitting arbitrary alarm IDs, thereby enabling deletion of alarms that do not belong to their own tenant. This vulnerability facilitates unauthorized bulk deletion of critical alerts, leading to a potential loss of safety and security measures within affected environments.

Affected Version(s)

openremote 0 < 1.24.2

openremote 1.24.2

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Forklit
vladkoniakhinmob
.